My contribution combines statistical concepts, ATT&CK-aligned activity, security log sources, illustrated explanations and detection-rule references. Worked examples expose the hypothesis, normalized fields, query, fixture observations and interpretation limits. Third-party incident reporting and MITRE material remain credited to their original publishers.