1200KM / tag
attack.t1021.002 — sigma-tag tag
36 related reference pages for sigma-tag: attack.t1021.002.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Access To ADMIN$ Network Share · sigma-rule
- CobaltStrike Service Installations - Security · sigma-rule
- CobaltStrike Service Installations - System · sigma-rule
- Copy From Or To Admin Share Or Sysvol Folder · sigma-rule
- DCERPC SMB Spoolss Named Pipe · sigma-rule
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security · sigma-rule
- First Time Seen Remote Named Pipe · sigma-rule
- First Time Seen Remote Named Pipe - Zeek · sigma-rule
- HackTool - NetExec File Indicators · sigma-rule
- HackTool - SharpMove Tool Execution · sigma-rule
- Impacket PsExec Execution · sigma-rule
- Metasploit Or Impacket Service Installation Via SMB PsExec · sigma-rule
- Metasploit SMB Authentication · sigma-rule
- Password Provided In Command Line Of Net.EXE · sigma-rule
- Potential CobaltStrike Service Installations - Registry · sigma-rule
- Potential DCOM InternetExplorer.Application DLL Hijack · sigma-rule
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load · sigma-rule
- Protected Storage Service Access · sigma-rule
- PUA - CSExec Default Named Pipe · sigma-rule
- PUA - RemCom Default Named Pipe · sigma-rule
- Remote Service Activity via SVCCTL Named Pipe · sigma-rule
- Rundll32 Execution Without Parameters · sigma-rule
- Rundll32 UNC Path Execution · sigma-rule
- SMB Create Remote File Admin Share · sigma-rule
- SMB Spoolss Name Piped Usage · sigma-rule
- smbexec.py Service Installation · sigma-rule
- Suspicious New-PSDrive to Admin Share · sigma-rule
- Suspicious PsExec Execution · sigma-rule
- Suspicious PsExec Execution - Zeek · sigma-rule
- T1047 Wmiprvse Wbemcomn DLL Hijack · sigma-rule
- Unsigned or Unencrypted SMB Connection to Share Established · sigma-rule
- Windows Admin Share Mount Via Net.EXE · sigma-rule
- Windows Internet Hosted WebDav Share Mount Via Net.EXE · sigma-rule
- Windows Share Mount Via Net.EXE · sigma-rule
- Wmiprvse Wbemcomn DLL Hijack · sigma-rule
- Wmiprvse Wbemcomn DLL Hijack - File · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.