1200KM / tag
stable — rule-status tag
75 related reference pages for rule-status: stable.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- A Member Was Added to a Security-Enabled Global Group · sigma-rule
- A Member Was Removed From a Security-Enabled Global Group · sigma-rule
- A New Trust Was Created To A Domain · sigma-rule
- A Security-Enabled Global Group Was Deleted · sigma-rule
- Addition of SID History to Active Directory Object · sigma-rule
- Antivirus Exploitation Framework Detection · sigma-rule
- Antivirus Hacktool Detection · sigma-rule
- Antivirus Password Dumper Detection · sigma-rule
- AWS EC2 Disable EBS Encryption · sigma-rule
- AWS SecurityHub Findings Evasion · sigma-rule
- Boot Configuration Tampering Via Bcdedit.EXE · sigma-rule
- CMSTP Execution Process Access · sigma-rule
- CMSTP Execution Process Creation · sigma-rule
- CMSTP Execution Registry Event · sigma-rule
- CMSTP UAC Bypass via COM Object Access · sigma-rule
- Credential Dumping Activity By Python Based Tool · sigma-rule
- Delete Volume Shadow Copies Via WMI With PowerShell · sigma-rule
- Django Framework Exceptions · sigma-rule
- Failed Code Integrity Checks · sigma-rule
- File Deletion · sigma-rule
- Fsutil Suspicious Invocation · sigma-rule
- HackTool - CrackMapExec Execution Patterns · sigma-rule
- HackTool - Empire PowerShell UAC Bypass · sigma-rule
- HackTool - Potential Impacket Lateral Movement Activity · sigma-rule
- HackTool - Rubeus Execution · sigma-rule
- HackTool - SecurityXploded Execution · sigma-rule
- Linux Crypto Mining Pool Connections · sigma-rule
- Linux Doas Conf File Creation · sigma-rule
- Linux Doas Tool Execution · sigma-rule
- Linux Logs Clearing Attempts · sigma-rule
- Microsoft Defender Tamper Protection Trigger · sigma-rule
- Monero Crypto Coin Mining Pool Lookup · sigma-rule
- Network Communication With Crypto Mining Pool · sigma-rule
- Overwriting the File with Dev Zero or Null · sigma-rule
- Pass the Hash Activity 2 · sigma-rule
- Password Change on Directory Service Restore Mode (DSRM) Account · sigma-rule
- Password Dumper Remote Thread in LSASS · sigma-rule
- Password Policy Discovery - Linux · sigma-rule
- Potential Crypto Mining Activity · sigma-rule
- Potential LSASS Process Dump Via Procdump · sigma-rule
- Potential Powershell ReverseShell Connection · sigma-rule
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell · sigma-rule
- Python SQL Exceptions · sigma-rule
- Relevant ClamAV Message · sigma-rule
- Remote File Copy · sigma-rule
- Remote LSASS Process Access Through Windows Remote Management · sigma-rule
- Ruby on Rails Framework Exceptions · sigma-rule
- Scheduled Task/Job At · sigma-rule
- Shadow Copies Deletion Using Operating Systems Utilities · sigma-rule
- Share And Session Enumeration Using Net.EXE · sigma-rule
- ShimCache Flush · sigma-rule
- Spring Framework Exceptions · sigma-rule
- Successful Account Login Via WMI · sigma-rule
- Suspicious Double Extension File Execution · sigma-rule
- Suspicious Eventlog Clearing or Configuration Change Activity · sigma-rule
- Suspicious Unsigned Thor Scanner Execution · sigma-rule
- System and Hardware Information Discovery · sigma-rule
- System Information Discovery · sigma-rule
- UAC Disabled · sigma-rule
- User Added to Local Administrator Group · sigma-rule
- VolumeShadowCopy Symlink Creation Via Mklink · sigma-rule
- Windows Defender AMSI Trigger Detected · sigma-rule
- Windows Defender Configuration Changes · sigma-rule
- Windows Defender Exclusions Added · sigma-rule
- Windows Defender Grace Period Expired · sigma-rule
- Windows Defender Malware And PUA Scanning Disabled · sigma-rule
- Windows Defender Real-time Protection Disabled · sigma-rule
- Windows Defender Real-Time Protection Failure/Restart · sigma-rule
- Windows Defender Submit Sample Feature Disabled · sigma-rule
- Windows Defender Threat Detected · sigma-rule
- Windows Defender Threat Detection Service Disabled · sigma-rule
- Windows Defender Virus Scanning Feature Disabled · sigma-rule
- Windows Update Error · sigma-rule
- WmiPrvSE Spawned A Process · sigma-rule
- Zerologon Exploitation Using Well-known Tools · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.