1200KM / tag
attack.t1021.003 — sigma-tag tag
13 related reference pages for sigma-tag: attack.t1021.003.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- BaaUpdate.exe Suspicious DLL Load · sigma-rule
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security · sigma-rule
- HackTool - Potential Impacket Lateral Movement Activity · sigma-rule
- MMC Spawning Windows Shell · sigma-rule
- MMC20 Lateral Movement · sigma-rule
- Potential DCOM InternetExplorer.Application DLL Hijack · sigma-rule
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load · sigma-rule
- Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp · sigma-rule
- Remote DCOM/WMI Lateral Movement · sigma-rule
- Suspicious BitLocker Access Agent Update Utility Execution · sigma-rule
- Suspicious Non PowerShell WSMAN COM Provider · sigma-rule
- Suspicious Speech Runtime Binary Child Process · sigma-rule
- Suspicious WSMAN Provider Image Loads · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.