Proposes TTPrint, a framework that separates candidate TTP generation from validation using a diverge-then-converge architecture, achieving both high recall and high precision on MITRE ATT&CK technique extraction from cyber threat intelligence reports. Existing LLM approaches hallucinate unsupported techniques; TTPrint's two-stage verification catches these. Applicable to automated threat intelligence pipelines.