← Intelligence-to-Detection Pipeline — From Threat Reports to Sigma Rules

Module Quiz

10 questions · Pass at 80%

Question 1 of 10

A threat report states: 'The attacker used PowerShell to download and execute the payload.' What additional specificity does a CTI analyst need to extract from the report to make this TTP actionable for a detection engineer?