Problem Statement
Explain how correlation rules in SIEM help identify multi-stage attacks.
Explanation
SIEM correlation rules connect multiple low-level alerts into a single incident narrative.
For example, repeated failed logins followed by privilege escalation and outbound traffic can be correlated into one attack chain, reducing alert fatigue and highlighting true threats.