1200KM / tag
attack.s0002 — sigma-tag tag
10 related reference pages for sigma-tag: attack.s0002.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Credential Dumping Attempt Via WerFault · sigma-rule
- HackTool - Generic Process Access · sigma-rule
- LSASS Access From Potentially White-Listed Processes · sigma-rule
- LSASS Memory Access by Tool With Dump Keyword In Name · sigma-rule
- Mimikatz DC Sync · sigma-rule
- Mimikatz Use · sigma-rule
- Potential Credential Dumping Activity Via LSASS · sigma-rule
- Potentially Suspicious GrantedAccess Flags On LSASS · sigma-rule
- Remote LSASS Process Access Through Windows Remote Management · sigma-rule
- Successful Overpass the Hash Attempt · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.