Write SIEM detection rules for a threat or TTP — SIGMA format, MITRE mapping, and test cases. Use when asked to "write a SIGMA rule", "build a detection rule for this TTP", or "map a SIEM rule to MITRE".