When designing a detection, the engineer must explicitly define the "Threat Object"—the artifact (IP, hash, filename) representing the malicious activity.
Extracting this allowing downstream integration with Threat Intelligence and SOAR playbooks for automated blocking.