1200KM / tag
critical — severity tag
64 related reference pages for severity: critical.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Active Directory Replication from Non Machine Account · sigma-rule
- AD Object WriteDAC Access · sigma-rule
- Antivirus Exploitation Framework Detection · sigma-rule
- Antivirus Password Dumper Detection · sigma-rule
- Antivirus Ransomware Detection · sigma-rule
- Audit CVE Event · sigma-rule
- Bad Opsec Powershell Code Artifacts · sigma-rule
- Bitbucket Unauthorized Access To A Resource · sigma-rule
- Bitbucket Unauthorized Full Data Export Triggered · sigma-rule
- Certificate Request Export to Exchange Webserver · sigma-rule
- Cobalt Strike DNS Beaconing · sigma-rule
- CobaltStrike Named Pipe · sigma-rule
- CobaltStrike Named Pipe Pattern Regex · sigma-rule
- CobaltStrike Service Installations - System · sigma-rule
- HackTool - BabyShark Agent Default URL Pattern · sigma-rule
- HackTool - Credential Dumping Tools Named Pipe Created · sigma-rule
- HackTool - DInjector PowerShell Cradle Execution · sigma-rule
- HackTool - Dumpert Process Dumper Default File · sigma-rule
- HackTool - Dumpert Process Dumper Execution · sigma-rule
- HackTool - Empire PowerShell UAC Bypass · sigma-rule
- HackTool - F-Secure C3 Load by Rundll32 · sigma-rule
- HackTool - Inveigh Execution · sigma-rule
- HackTool - Inveigh Execution Artefacts · sigma-rule
- HackTool - Koh Default Named Pipe · sigma-rule
- HackTool - Mimikatz Kirbi File Creation · sigma-rule
- HackTool - PurpleSharp Execution · sigma-rule
- HackTool - QuarksPwDump Dump File · sigma-rule
- HackTool - Rubeus Execution · sigma-rule
- HackTool - SafetyKatz Execution · sigma-rule
- HackTool - SecurityXploded Execution · sigma-rule
- HackTool - SharpUp PrivEsc Tool Execution · sigma-rule
- HackTool - Sliver C2 Implant Activity Pattern · sigma-rule
- HackTool - SysmonEOP Execution · sigma-rule
- HackTool - Windows Credential Editor (WCE) Execution · sigma-rule
- Hacktool Execution - Imphash · sigma-rule
- Linux Reverse Shell Indicator · sigma-rule
- Mailbox Export to Exchange Webserver · sigma-rule
- Malicious Named Pipe Created · sigma-rule
- Moriya Rootkit - System · sigma-rule
- Persistence Via Sticky Key Backdoor · sigma-rule
- Possible Coin Miner CPU Priority Param · sigma-rule
- Potential Credential Dumping Via LSASS Process Clone · sigma-rule
- Potential Credential Dumping Via LSASS SilentProcessExit Technique · sigma-rule
- Potential DCOM InternetExplorer.Application DLL Hijack · sigma-rule
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load · sigma-rule
- Potential SMB Relay Attack Tool Execution · sigma-rule
- ProxyLogon MSExchange OabVirtualDirectory · sigma-rule
- PwnDrp Access · sigma-rule
- Registry Entries For Azorult Malware · sigma-rule
- Renamed Whoami Execution · sigma-rule
- Silence.EDA Detection · sigma-rule
- Sticky Key Like Backdoor Execution · sigma-rule
- Sticky Key Like Backdoor Usage - Registry · sigma-rule
- Suspicious Cobalt Strike DNS Beaconing - DNS Client · sigma-rule
- Suspicious Cobalt Strike DNS Beaconing - Sysmon · sigma-rule
- TrustedPath UAC Bypass Pattern · sigma-rule
- WCE wceaux.dll Access · sigma-rule
- Webshell Remote Command Execution · sigma-rule
- Win Susp Computer Name Containing Samtheadmin · sigma-rule
- Windows Credential Editor Registry · sigma-rule
- WMI Backdoor Exchange Transport Agent · sigma-rule
- Wmiexec Default Output File · sigma-rule
- Wmiprvse Wbemcomn DLL Hijack - File · sigma-rule
- Zerologon Exploitation Using Well-known Tools · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.