1200KM / tag
experimental — rule-status tag
204 related reference pages for rule-status: experimental.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- ADExplorer Writing Complete AD Snapshot Into .dat File · sigma-rule
- AMSI Disabled via Registry Modification · sigma-rule
- ASLR Disabled Via Sysctl or Direct Syscall - Linux · sigma-rule
- Attempts of Kerberos Coercion Via DNS SPN Spoofing · sigma-rule
- Audit Rules Deleted Via Auditctl · sigma-rule
- AWS ConsoleLogin Failed Authentication · sigma-rule
- AWS GuardDuty Detector Deleted Or Updated · sigma-rule
- AWS Key Pair Import Activity · sigma-rule
- AWS KMS Imported Key Material Usage · sigma-rule
- AWS SAML Provider Deletion Activity · sigma-rule
- AWS STS GetCallerIdentity Enumeration Via TruffleHog · sigma-rule
- AWS Successful Console Login Without MFA · sigma-rule
- Azure Login Bypassing Conditional Access Policies · sigma-rule
- BaaUpdate.exe Suspicious DLL Load · sigma-rule
- Cisco Dot1x Disabled · sigma-rule
- Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall · sigma-rule
- Clfs.SYS Loaded By Process Located In a Potential Suspicious Location · sigma-rule
- Cmd Launched with Hidden Start Flags to Suspicious Targets · sigma-rule
- COM Object Hijacking Via Modification Of Default System CLSID Default Value · sigma-rule
- Crash Dump Created By Operating System · sigma-rule
- Curl File Upload To File Sharing Websites · sigma-rule
- Deno Runtime Spawns Shell Or Scripting Interpreter · sigma-rule
- Devcon Execution Disabling VMware VMCI Device · sigma-rule
- Disabling Windows Defender WMI Autologger Session via Reg.exe · sigma-rule
- DMSA Link Attributes Modified · sigma-rule
- DMSA Service Account Created in Specific OUs - PowerShell · sigma-rule
- DNS Query by Finger Utility · sigma-rule
- DNS Query Request By QuickAssist.EXE · sigma-rule
- DNS Query To Common Malware Hosting and Shortener Services · sigma-rule
- File Access Of Signal Desktop Sensitive Data · sigma-rule
- FileFix - Command Evidence in TypedPaths · sigma-rule
- FortiGate - Firewall Address Object Added · sigma-rule
- FortiGate - New Administrator Account Created · sigma-rule
- FortiGate - New Firewall Policy Added · sigma-rule
- FortiGate - New Local User Created · sigma-rule
- FortiGate - New VPN SSL Web Portal Added · sigma-rule
- FortiGate - VPN SSL Settings Modified · sigma-rule
- GitHub Repository Pages Site Changed to Public · sigma-rule
- Google Workspace Government Attack Warning · sigma-rule
- Google Workspace Out Of Domain Email Forwarding · sigma-rule
- HackTool - Doppelanger LSASS Dumper Execution · sigma-rule
- Hacktool - EDR-Freeze Execution · sigma-rule
- HackTool - HollowReaper Execution · sigma-rule
- HackTool - Impacket File Indicators · sigma-rule
- HackTool - NetExec Execution · sigma-rule
- HackTool - NetExec File Indicators · sigma-rule
- HackTool - WSASS Execution · sigma-rule
- HKTL - SharpSuccessor Privilege Escalation Tool Execution · sigma-rule
- Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine · sigma-rule
- IIS WebServer Log Deletion via CommandLine Utilities · sigma-rule
- Indirect Command Execution via SFTP ProxyCommand · sigma-rule
- Installation of WSL Kali-Linux · sigma-rule
- ISATAP Router Address Was Set · sigma-rule
- Kaspersky Endpoint Security Stopped Via CommandLine - Linux · sigma-rule
- Kubernetes Potential Enumeration Activity · sigma-rule
- Legitimate Application Writing Files In Uncommon Location · sigma-rule
- Linux Setgid Capability Set on a Binary via Setcap Utility · sigma-rule
- Linux Setuid Capability Set on a Binary via Setcap Utility · sigma-rule
- Linux Sudo Chroot Execution · sigma-rule
- LSASS Process Crashed - Application · sigma-rule
- Mask System Power Settings Via Systemctl · sigma-rule
- MMC Executing Files with Reversed Extensions Using RTLO Abuse · sigma-rule
- MMC Loading Script Engines DLLs · sigma-rule
- Modification or Deletion of an AWS RDS Cluster · sigma-rule
- MSSQL Destructive Query · sigma-rule
- Network Connection Initiated via Finger.EXE · sigma-rule
- New Cron File Created · sigma-rule
- New DMSA Service Account Created in Specific OUs · sigma-rule
- New RUN Key Pointing to Suspicious Folder · sigma-rule
- NodeJS Execution of JavaScript File · sigma-rule
- Non-Mail Client IMAP Connection Hunt Starter · sigma-rule
- Notepad Password Files Discovery · sigma-rule
- Notepad++ Updater DNS Query to Uncommon Domains · sigma-rule
- Obfuscated PowerShell MSI Install via WindowsInstaller COM · sigma-rule
- OpenCanary - Host Port Scan (SYN Scan) · sigma-rule
- OpenCanary - NMAP FIN Scan · sigma-rule
- OpenCanary - NMAP NULL Scan · sigma-rule
- OpenCanary - NMAP OS Scan · sigma-rule
- OpenCanary - NMAP XMAS Scan · sigma-rule
- OpenCanary - RDP New Connection Attempt · sigma-rule
- OpenEDR Spawning Command Shell · sigma-rule
- Password Set to Never Expire via WMI · sigma-rule
- Potential Abuse of Linux Magic System Request Key · sigma-rule
- Potential ClickFix Execution Pattern - Registry · sigma-rule
- Potential Hello-World Scraper Botnet Activity · sigma-rule
- Potential JLI.dll Side-Loading · sigma-rule
- Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation · sigma-rule
- Potential Lateral Movement via Windows Remote Shell · sigma-rule
- Potential PowerShell Console History Access Attempt via History File · sigma-rule
- Potential SSH Tunnel Persistence Install Using A Scheduled Task · sigma-rule
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock · sigma-rule
- Potential Vcruntime140 DLL Sideloading · sigma-rule
- Potentially Suspicious Child Processes Spawned by ConHost · sigma-rule
- Potentially Suspicious File Creation by OpenEDR's ITSMService · sigma-rule
- Potentially Suspicious Inline JavaScript Execution via NodeJS Binary · sigma-rule
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction' · sigma-rule
- PowerShell MSI Install via WindowsInstaller COM From Remote Location · sigma-rule
- PPL Tampering Via WerFaultSecure · sigma-rule
- Process Execution From Shared Memory Directory · sigma-rule
- Proxy Execution via Vshadow · sigma-rule
- PUA - AdFind.EXE Execution · sigma-rule
- PUA - AWS TruffleHog Execution · sigma-rule
- PUA - Kernel Driver Utility (KDU) Execution · sigma-rule
- PUA - Memory Dump Mount Via MemProcFS · sigma-rule
- PUA - Restic Backup Tool Execution · sigma-rule
- PUA - TruffleHog Execution · sigma-rule
- PUA - TruffleHog Execution - Linux · sigma-rule
- Python One-Liners with Base64 Decoding · sigma-rule
- Python One-Liners with Base64 Decoding - Linux · sigma-rule
- Python WebServer Execution - Linux · sigma-rule
- QuickAssist Execution · sigma-rule
- RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class · sigma-rule
- RegAsm.EXE Execution Without CommandLine Flags or Files · sigma-rule
- Registry Enumeration via WMI Stdregprov · sigma-rule
- Registry Export of Third-Party Credentials · sigma-rule
- Registry Manipulation via WMI Stdregprov · sigma-rule
- Registry Modification Attempt Via VBScript · sigma-rule
- Registry Modification Attempt Via VBScript - PowerShell · sigma-rule
- Registry Modification for OCI DLL Redirection · sigma-rule
- Registry Tampering by Potentially Suspicious Processes · sigma-rule
- Remote Access Tool - AnyDesk Incoming Connection · sigma-rule
- Remote Access Tool - Potential MeshAgent Execution - MacOS · sigma-rule
- Remote Access Tool - Potential MeshAgent Execution - Windows · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - MacOS · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - Windows · sigma-rule
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server · sigma-rule
- Renamed Schtasks Execution · sigma-rule
- RunMRU Registry Key Deletion · sigma-rule
- RunMRU Registry Key Deletion - Registry · sigma-rule
- Scheduled Task Creation Masquerading as System Processes · sigma-rule
- Scheduled Task Creation with Curl and PowerShell Execution Combo · sigma-rule
- Script Interpreter Spawning Credential Scanner - Linux · sigma-rule
- Script Interpreter Spawning Credential Scanner - Windows · sigma-rule
- Security Event Logging Disabled via MiniNt Registry Key - Process · sigma-rule
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set · sigma-rule
- Service Startup Type Change Via Wmic.EXE · sigma-rule
- Shell Execution via Rsync - Linux · sigma-rule
- Special File Creation via Mknod Syscall · sigma-rule
- Suspicious ArcSOC.exe Child Process · sigma-rule
- Suspicious Autorun Registry Modified via WMI · sigma-rule
- Suspicious Binaries and Scripts in Public Folder · sigma-rule
- Suspicious BitLocker Access Agent Update Utility Execution · sigma-rule
- Suspicious CertReq Command to Download · sigma-rule
- Suspicious Child Process of Notepad++ Updater - GUP.Exe · sigma-rule
- Suspicious ClickFix/FileFix Execution Pattern · sigma-rule
- Suspicious Deno File Written from Remote Source · sigma-rule
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing · sigma-rule
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network · sigma-rule
- Suspicious Download and Execute Pattern via Curl/Wget · sigma-rule
- Suspicious Email Delivered In Microsoft 365 · sigma-rule
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix · sigma-rule
- Suspicious File Access to Browser Credential Storage · sigma-rule
- Suspicious File Created by ArcSOC.exe · sigma-rule
- Suspicious File Created in Outlook Temporary Directory · sigma-rule
- Suspicious File Write to SharePoint Layouts Directory · sigma-rule
- Suspicious File Write to Webapps Root Directory · sigma-rule
- Suspicious FileFix Execution Pattern · sigma-rule
- Suspicious Filename with Embedded Base64 Commands · sigma-rule
- Suspicious Invocation of Shell via Rsync · sigma-rule
- Suspicious Kerberos Ticket Request via CLI · sigma-rule
- Suspicious LNK Command-Line Padding with Whitespace Characters · sigma-rule
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location · sigma-rule
- Suspicious Login Activity Classified By Google · sigma-rule
- Suspicious Non-Browser Network Communication With Google API · sigma-rule
- Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze · sigma-rule
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs · sigma-rule
- Suspicious Shell Open Command Registry Modification · sigma-rule
- Suspicious Space Characters in RunMRU Registry Path - ClickFix · sigma-rule
- Suspicious Space Characters in TypedPaths Registry Path - FileFix · sigma-rule
- Suspicious Speech Runtime Binary Child Process · sigma-rule
- Suspicious Uninstall of Windows Defender Feature via PowerShell · sigma-rule
- Suspicious Usage of For Loop with Recursive Directory Search in CMD · sigma-rule
- Suspicious Velociraptor Child Process · sigma-rule
- System Info Discovery via Sysinfo Syscall · sigma-rule
- System Information Discovery via Registry Queries · sigma-rule
- System Language Discovery via Reg.Exe · sigma-rule
- System Restore Registry Modification via CommandLine · sigma-rule
- Trusted Path Bypass via Windows Directory Spoofing · sigma-rule
- Uncommon File Created by Notepad++ Updater Gup.EXE · sigma-rule
- Uncommon Svchost Command Line Parameter · sigma-rule
- Unsigned .node File Loaded · sigma-rule
- Unsigned or Unencrypted SMB Connection to Share Established · sigma-rule
- User Shell Folders Registry Modification via CommandLine · sigma-rule
- Vulnerable Driver Blocklist Registry Tampering Via CommandLine · sigma-rule
- WFP Filter Added via Registry · sigma-rule
- Windows AMSI Related Registry Tampering Via CommandLine · sigma-rule
- Windows AppX Deployment Full Trust Package Installation · sigma-rule
- Windows AppX Deployment Unsigned Package Installation · sigma-rule
- Windows Credential Guard Disabled - Registry · sigma-rule
- Windows Credential Guard Registry Tampering Via CommandLine · sigma-rule
- Windows Credential Guard Related Registry Value Deleted - Registry · sigma-rule
- Windows Default Domain GPO Modification · sigma-rule
- Windows Default Domain GPO Modification via GPME · sigma-rule
- Windows Defender Context Menu Removed · sigma-rule
- Windows Defender Threat Severity Default Action Modified · sigma-rule
- Windows Event Log Access Tampering Via Registry · sigma-rule
- Windows EventLog Autologger Session Registry Modification Via CommandLine · sigma-rule
- Windows MSIX Package Support Framework AI_STUBS Execution · sigma-rule
- Windows Recovery Environment Disabled Via Reagentc · sigma-rule
- Windows Vulnerable Driver Blocklist Disabled · sigma-rule
- WinRAR Creating Files in Startup Locations · sigma-rule
- Winrs Local Command Execution · sigma-rule
- Wlrmdr.EXE Uncommon Argument Or Child Process · sigma-rule
- WSL Kali-Linux Usage · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.