SIEM

Signatures should be mapped to use cases based on grouping that makes sense. This mapping allows the investigator to review recommended response actions. A good start would be using MITRE ATT&CK framework Tactics as Use Cases for signatures.

These less-technical use cases should also be considered for addition into your use case library: