1200KM / tag
attack.initial-access — sigma-tag tag
202 related reference pages for sigma-tag: attack.initial-access.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Account Created And Deleted Within A Close Time Frame · sigma-rule
- Account Disabled or Blocked for Sign in Attempts · sigma-rule
- Account Tampering - Suspicious Failed Logon Reasons · sigma-rule
- Activity From Anonymous IP Address · sigma-rule
- Admin User Remote Logon · sigma-rule
- Apache Threading Error · sigma-rule
- Application AppID Uri Configuration Changes · sigma-rule
- Application URI Configuration Changes · sigma-rule
- Application Using Device Code Authentication Flow · sigma-rule
- Applications That Are Using ROPC Authentication Flow · sigma-rule
- Arbitrary Shell Command Execution Via Settingcontent-Ms · sigma-rule
- Atypical Travel · sigma-rule
- Authentications To Important Apps Using Single Factor Authentication · sigma-rule
- AWS IAM S3Browser LoginProfile Creation · sigma-rule
- AWS IAM S3Browser Templated S3 Bucket Policy Creation · sigma-rule
- AWS IAM S3Browser User or AccessKey Creation · sigma-rule
- AWS Key Pair Import Activity · sigma-rule
- AWS Root Credentials · sigma-rule
- AWS SAML Provider Deletion Activity · sigma-rule
- AWS Successful Console Login Without MFA · sigma-rule
- AWS Suspicious SAML Activity · sigma-rule
- Azure AD Only Single Factor Authentication Required · sigma-rule
- Azure AD Threat Intelligence · sigma-rule
- Azure Domain Federation Settings Modified · sigma-rule
- Azure Kubernetes Admission Controller · sigma-rule
- Azure Login Bypassing Conditional Access Policies · sigma-rule
- Azure Subscription Permission Elevation Via ActivityLogs · sigma-rule
- Azure Subscription Permission Elevation Via AuditLogs · sigma-rule
- Azure Unusual Authentication Interruption · sigma-rule
- Bitbucket User Login Failure · sigma-rule
- Bitlocker Key Retrieval · sigma-rule
- Changes To PIM Settings · sigma-rule
- Cisco BGP Authentication Failures · sigma-rule
- Cisco LDP Authentication Failures · sigma-rule
- Cross Site Scripting Strings · sigma-rule
- Device Installation Blocked · sigma-rule
- Device Registration or Join Without MFA · sigma-rule
- Disk Image Mounting Via Hdiutil - MacOS · sigma-rule
- Django Framework Exceptions · sigma-rule
- DMSA Link Attributes Modified · sigma-rule
- DMSA Service Account Created in Specific OUs - PowerShell · sigma-rule
- DNS Query Request By QuickAssist.EXE · sigma-rule
- DNS Query to External Service Interaction Domains · sigma-rule
- Download From Suspicious TLD - Blacklist · sigma-rule
- Download From Suspicious TLD - Whitelist · sigma-rule
- External Disk Drive Or USB Storage Device Was Recognized By The System · sigma-rule
- External Remote RDP Logon from Public IP · sigma-rule
- External Remote SMB Logon from Public IP · sigma-rule
- F5 BIG-IP iControl Rest API Command Execution - Proxy · sigma-rule
- F5 BIG-IP iControl Rest API Command Execution - Webserver · sigma-rule
- Failed Authentications From Countries You Do Not Operate Out Of · sigma-rule
- Failed Logon From Public IP · sigma-rule
- Flash Player Update from Suspicious Location · sigma-rule
- FortiGate - New VPN SSL Web Portal Added · sigma-rule
- FortiGate - VPN SSL Settings Modified · sigma-rule
- Github New Secret Created · sigma-rule
- Github Self Hosted Runner Changes Detected · sigma-rule
- Github SSH Certificate Configuration Changed · sigma-rule
- Google Cloud Kubernetes Admission Controller · sigma-rule
- Google Workspace Government Attack Warning · sigma-rule
- Guest Account Enabled Via Sysadminctl · sigma-rule
- Guest User Invited By Non Approved Inviters · sigma-rule
- Guest Users Invited To Tenant By Non Approved Inviters · sigma-rule
- Hack Tool User Agent · sigma-rule
- HTML Help HH.EXE Suspicious Child Process · sigma-rule
- Huawei BGP Authentication Failures · sigma-rule
- Impossible Travel · sigma-rule
- Increased Failed Authentications Of Any Type · sigma-rule
- Ingress/Egress Security Group Modification · sigma-rule
- Invalid PIM License · sigma-rule
- ISATAP Router Address Was Set · sigma-rule
- ISO File Created Within Temp Folders · sigma-rule
- ISO Image Mounted · sigma-rule
- ISO or Image Mount Indicator in Recent Files · sigma-rule
- Java Payload Strings · sigma-rule
- JNDIExploit Pattern · sigma-rule
- Juniper BGP Missing MD5 · sigma-rule
- Kubernetes Admission Controller Modification · sigma-rule
- LoadBalancer Security Group Modification · sigma-rule
- Login to Disabled Account · sigma-rule
- Logon from a Risky IP Address · sigma-rule
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure · sigma-rule
- Measurable Increase Of Successful Authentications · sigma-rule
- Microsoft 365 - Impossible Travel Activity · sigma-rule
- Microsoft 365 - User Restricted from Sending Email · sigma-rule
- Multifactor Authentication Denied · sigma-rule
- Multifactor Authentication Interrupted · sigma-rule
- New Country · sigma-rule
- New DMSA Service Account Created in Specific OUs · sigma-rule
- Notepad++ Updater DNS Query to Uncommon Domains · sigma-rule
- Octopus Scanner Malware · sigma-rule
- Office Macro File Creation · sigma-rule
- Office Macro File Creation From Suspicious Process · sigma-rule
- Office Macro File Download · sigma-rule
- Okta FastPass Phishing Detection · sigma-rule
- Okta New Admin Console Behaviours · sigma-rule
- OMIGOD SCX RunAsProvider ExecuteScript · sigma-rule
- OMIGOD SCX RunAsProvider ExecuteShellCommand · sigma-rule
- OpenCanary - FTP Login Attempt · sigma-rule
- OpenCanary - HTTP GET Request · sigma-rule
- OpenCanary - HTTP POST Login Attempt · sigma-rule
- OpenCanary - HTTPPROXY Login Attempt · sigma-rule
- OpenCanary - RDP New Connection Attempt · sigma-rule
- OpenCanary - SSH Login Attempt · sigma-rule
- OpenCanary - SSH New Connection Attempt · sigma-rule
- OpenCanary - Telnet Login Attempt · sigma-rule
- Outdated Dependency Or Vulnerability Alert Disabled · sigma-rule
- Password Protected ZIP File Opened (Email Attachment) · sigma-rule
- Password Provided In Command Line Of Net.EXE · sigma-rule
- Password Reset By User Account · sigma-rule
- Path Traversal Exploitation Attempts · sigma-rule
- Phishing Pattern ISO in Archive · sigma-rule
- PIM Alert Setting Changes To Disabled · sigma-rule
- PIM Approvals And Deny Elevation · sigma-rule
- Potential Initial Access via DLL Search Order Hijacking · sigma-rule
- Potential JNDI Injection Exploitation In JVM Based Application · sigma-rule
- Potential Local File Read Vulnerability In JVM Based Application · sigma-rule
- Potential Malicious Usage of CloudTrail System Manager · sigma-rule
- Potential MFA Bypass Using Legacy Client Authentication · sigma-rule
- Potential OGNL Injection Exploitation In JVM Based Application · sigma-rule
- Potential RCE Exploitation Attempt In NodeJS · sigma-rule
- Potential Server Side Template Injection In Velocity · sigma-rule
- Potential SpEL Injection In Spring Framework · sigma-rule
- Potential XXE Exploitation Attempt In JVM Based Application · sigma-rule
- Privileged Account Creation · sigma-rule
- Process Execution Error In JVM Based Application · sigma-rule
- Python SQL Exceptions · sigma-rule
- RDS Database Security Group Modification · sigma-rule
- Remote Access Tool - ScreenConnect Installation Execution · sigma-rule
- Remote Access Tool - ScreenConnect Server Web Shell Execution · sigma-rule
- Remote Access Tool - Team Viewer Session Started On Linux Host · sigma-rule
- Remote Access Tool - Team Viewer Session Started On MacOS Host · sigma-rule
- Remote Access Tool - Team Viewer Session Started On Windows Host · sigma-rule
- Roles Activated Too Frequently · sigma-rule
- Roles Activation Doesn't Require MFA · sigma-rule
- Roles Are Not Being Used · sigma-rule
- Roles Assigned Outside PIM · sigma-rule
- Root Account Enable Via Dsenableroot · sigma-rule
- Ruby on Rails Framework Exceptions · sigma-rule
- Running Chrome VPN Extensions via the Registry 2 VPN Extension · sigma-rule
- Sign-in Failure Due to Conditional Access Requirements Not Met · sigma-rule
- Sign-ins by Unknown Devices · sigma-rule
- Sign-ins from Non-Compliant Devices · sigma-rule
- Spring Framework Exceptions · sigma-rule
- SQL Injection Strings In URI · sigma-rule
- Stale Accounts In A Privileged Role · sigma-rule
- Successful Authentications From Countries You Do Not Operate Out Of · sigma-rule
- Successful IIS Shortname Fuzzing Scan · sigma-rule
- Suspicious Browser Activity · sigma-rule
- Suspicious Browser Child Process - MacOS · sigma-rule
- Suspicious Child Process of Notepad++ Updater - GUP.Exe · sigma-rule
- Suspicious Child Process Of SQL Server · sigma-rule
- Suspicious Computer Machine Password by PowerShell · sigma-rule
- Suspicious Double Extension File Execution · sigma-rule
- Suspicious Email Delivered In Microsoft 365 · sigma-rule
- Suspicious Execution From Outlook Temporary Folder · sigma-rule
- Suspicious Execution via macOS Script Editor · sigma-rule
- Suspicious External WebDAV Execution · sigma-rule
- Suspicious File Created by ArcSOC.exe · sigma-rule
- Suspicious File Created in Outlook Temporary Directory · sigma-rule
- Suspicious File Drop by Exchange · sigma-rule
- Suspicious File Write to SharePoint Layouts Directory · sigma-rule
- Suspicious File Write to Webapps Root Directory · sigma-rule
- Suspicious HH.EXE Execution · sigma-rule
- Suspicious HWP Sub Processes · sigma-rule
- Suspicious LNK Command-Line Padding with Whitespace Characters · sigma-rule
- Suspicious Login Activity Classified By Google · sigma-rule
- Suspicious Microsoft OneNote Child Process · sigma-rule
- Suspicious MSExchangeMailboxReplication ASPX Write · sigma-rule
- Suspicious Named Error · sigma-rule
- Suspicious OpenSSH Daemon Error · sigma-rule
- Suspicious Process By Web Server Process · sigma-rule
- Suspicious Processes Spawned by WinRM · sigma-rule
- Suspicious Remote Logon with Explicit Credentials · sigma-rule
- Suspicious SignIns From A Non Registered Device · sigma-rule
- Suspicious SQL Error Messages · sigma-rule
- Suspicious SQL Query · sigma-rule
- Suspicious User-Agents Related To Recon Tools · sigma-rule
- Suspicious VSFTPD Error Messages · sigma-rule
- Temporary Access Pass Added To An Account · sigma-rule
- Terminal Service Process Spawn · sigma-rule
- Too Many Global Admins · sigma-rule
- Uncommon File Created by Notepad++ Updater Gup.EXE · sigma-rule
- Unfamiliar Sign-In Properties · sigma-rule
- Unusual Child Process of dns.exe · sigma-rule
- Unusual File Deletion by Dns.exe · sigma-rule
- Unusual File Modification by dns.exe · sigma-rule
- USB Device Plugged · sigma-rule
- Use of Legacy Authentication Protocols · sigma-rule
- User Access Blocked by Azure Conditional Access · sigma-rule
- User Added To Admin Group Via Dscl · sigma-rule
- User Added To Admin Group Via DseditGroup · sigma-rule
- User Added To Admin Group Via Sysadminctl · sigma-rule
- User Added to an Administrator's Azure AD Role · sigma-rule
- User Added to Local Administrator Group · sigma-rule
- User Added To Privilege Role · sigma-rule
- User Added to Remote Desktop Users Group · sigma-rule
- User State Changed From Guest To Member · sigma-rule
- Users Added to Global or Device Admin Roles · sigma-rule
- Users Authenticating To Other Azure AD Tenants · sigma-rule
- Win Susp Computer Name Containing Samtheadmin · sigma-rule
- Windows Registry Trust Record Modification · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.