1200KM / tag
attack.t1003.001 — sigma-tag tag
73 related reference pages for sigma-tag: attack.t1003.001.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Antivirus Password Dumper Detection · sigma-rule
- CreateDump Process Dump · sigma-rule
- Cred Dump Tools Dropped Files · sigma-rule
- Credential Dumping Activity By Python Based Tool · sigma-rule
- Credential Dumping Attempt Via WerFault · sigma-rule
- Credential Dumping Tools Service Execution - Security · sigma-rule
- Credential Dumping Tools Service Execution - System · sigma-rule
- Dumping Process via Sqldumper.exe · sigma-rule
- DumpMinitool Execution · sigma-rule
- HackTool - CrackMapExec File Indicators · sigma-rule
- HackTool - CrackMapExec Process Patterns · sigma-rule
- HackTool - CreateMiniDump Execution · sigma-rule
- HackTool - Credential Dumping Tools Named Pipe Created · sigma-rule
- HackTool - Doppelanger LSASS Dumper Execution · sigma-rule
- HackTool - Dumpert Process Dumper Default File · sigma-rule
- HackTool - Dumpert Process Dumper Execution · sigma-rule
- HackTool - Generic Process Access · sigma-rule
- HackTool - HandleKatz Duplicating LSASS Handle · sigma-rule
- HackTool - HandleKatz LSASS Dumper Execution · sigma-rule
- HackTool - Impacket File Indicators · sigma-rule
- HackTool - Inveigh Execution · sigma-rule
- HackTool - Mimikatz Execution · sigma-rule
- HackTool - SafetyKatz Dump Indicator · sigma-rule
- HackTool - SafetyKatz Execution · sigma-rule
- HackTool - Windows Credential Editor (WCE) Execution · sigma-rule
- HackTool - WSASS Execution · sigma-rule
- HackTool - XORDump Execution · sigma-rule
- LSASS Access Detected via Attack Surface Reduction · sigma-rule
- LSASS Access From Non System Account · sigma-rule
- LSASS Access From Potentially White-Listed Processes · sigma-rule
- LSASS Dump Keyword In CommandLine · sigma-rule
- Lsass Full Dump Request Via DumpType Registry Settings · sigma-rule
- LSASS Memory Access by Tool With Dump Keyword In Name · sigma-rule
- Lsass Memory Dump via Comsvcs DLL · sigma-rule
- LSASS Process Crashed - Application · sigma-rule
- LSASS Process Dump Artefact In CrashDumps Folder · sigma-rule
- LSASS Process Memory Dump Creation Via Taskmgr.EXE · sigma-rule
- LSASS Process Memory Dump Files · sigma-rule
- Mimikatz Use · sigma-rule
- Password Dumper Activity on LSASS · sigma-rule
- Password Dumper Remote Thread in LSASS · sigma-rule
- Potential Adplus.EXE Abuse · sigma-rule
- Potential Credential Dumping Activity Via LSASS · sigma-rule
- Potential Credential Dumping Attempt Via PowerShell Remote Thread · sigma-rule
- Potential Credential Dumping Via LSASS Process Clone · sigma-rule
- Potential Credential Dumping Via LSASS SilentProcessExit Technique · sigma-rule
- Potential Credential Dumping Via WER · sigma-rule
- Potential LSASS Process Dump Via Procdump · sigma-rule
- Potential SysInternals ProcDump Evasion · sigma-rule
- Potential Windows Defender AV Bypass Via Dump64.EXE Rename · sigma-rule
- Potentially Suspicious AccessMask Requested From LSASS · sigma-rule
- Potentially Suspicious GrantedAccess Flags On LSASS · sigma-rule
- PowerShell Get-Process LSASS in ScriptBlock · sigma-rule
- PPL Tampering Via WerFaultSecure · sigma-rule
- Procdump Execution · sigma-rule
- Process Access via TrolleyExpress Exclusion · sigma-rule
- Process Memory Dump Via Comsvcs.DLL · sigma-rule
- Process Memory Dump via RdrLeakDiag.EXE · sigma-rule
- PUA - Memory Dump Mount Via MemProcFS · sigma-rule
- Remote LSASS Process Access Through Windows Remote Management · sigma-rule
- Renamed CreateDump Utility Execution · sigma-rule
- Suspicious DumpMinitool Execution · sigma-rule
- Suspicious LSASS Access Via MalSecLogon · sigma-rule
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs · sigma-rule
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32 · sigma-rule
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded · sigma-rule
- Time Travel Debugging Utility Usage · sigma-rule
- Time Travel Debugging Utility Usage - Image · sigma-rule
- Transferring Files with Credential Data via Network Shares · sigma-rule
- Transferring Files with Credential Data via Network Shares - Zeek · sigma-rule
- Unsigned Image Loaded Into LSASS Process · sigma-rule
- WerFault LSASS Process Memory Dump · sigma-rule
- Windows Credential Editor Registry · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.