← Intelligence-to-Detection Pipeline — From Threat Reports to Sigma Rules
Module Quiz
10 questions · Pass at 80%
Question 1 of 10
A threat report states: 'The attacker used PowerShell to download and execute the payload.' What additional specificity does a CTI analyst need to extract from the report to make this TTP actionable for a detection engineer?