1200KM / tag
attack.t1003.003 — sigma-tag tag
23 related reference pages for sigma-tag: attack.t1003.003.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Copying Sensitive Files with Credential Data · sigma-rule
- Create Volume Shadow Copy with Powershell · sigma-rule
- Cred Dump Tools Dropped Files · sigma-rule
- Esentutl Gather Credentials · sigma-rule
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) · sigma-rule
- NTDS Exfiltration Filename Patterns · sigma-rule
- NTDS.DIT Created · sigma-rule
- NTDS.DIT Creation By Uncommon Parent Process · sigma-rule
- NTDS.DIT Creation By Uncommon Process · sigma-rule
- Ntdsutil Abuse · sigma-rule
- Possible Impacket SecretDump Remote Activity · sigma-rule
- Possible Impacket SecretDump Remote Activity - Zeek · sigma-rule
- PUA - DIT Snapshot Viewer · sigma-rule
- Sensitive File Dump Via Print.EXE · sigma-rule
- Sensitive File Dump Via Wbadmin.EXE · sigma-rule
- Sensitive File Recovery From Backup Via Wbadmin.EXE · sigma-rule
- Shadow Copies Creation Using Operating Systems Utilities · sigma-rule
- Suspicious Get-ADDBAccount Usage · sigma-rule
- Suspicious Process Patterns NTDS.DIT Exfil · sigma-rule
- Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe) · sigma-rule
- Transferring Files with Credential Data via Network Shares · sigma-rule
- Transferring Files with Credential Data via Network Shares - Zeek · sigma-rule
- VolumeShadowCopy Symlink Creation Via Mklink · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.