Loading interactive filters…
1200KM / detection
T1127.003 JamPlus — Detection Rules
Detection workspace for T1127.003 JamPlus: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0585 Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)
AN1610 Analytic 1610
Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1127.003 simulation workspace
- File Creation · DC0039
- Network Connection Creation · DC0082
- Process Creation · DC0032
- Process Metadata · DC0034
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.