1200KM / tag
attack.t1027 — sigma-tag tag
87 related reference pages for sigma-tag: attack.t1027.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Base64 Encoded PowerShell Command Detected · sigma-rule
- Certificate Exported Via Certutil.EXE · sigma-rule
- ConvertTo-SecureString Cmdlet Usage Via CommandLine · sigma-rule
- Decode Base64 Encoded Text · sigma-rule
- Decode Base64 Encoded Text -MacOs · sigma-rule
- File Decoded From Base64/Hex Via Certutil.EXE · sigma-rule
- File Encoded To Base64 Via Certutil.EXE · sigma-rule
- File In Suspicious Location Encoded To Base64 Via Certutil.EXE · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - Security · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - System · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - System · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - Security · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - System · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - Security · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - System · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Powershell · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Security · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR+ Launcher · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - Security · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System · sigma-rule
- Invoke-Obfuscation Via Stdin · sigma-rule
- Invoke-Obfuscation Via Stdin - Powershell · sigma-rule
- Invoke-Obfuscation Via Stdin - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Stdin - Security · sigma-rule
- Invoke-Obfuscation Via Stdin - System · sigma-rule
- Invoke-Obfuscation Via Use Clip · sigma-rule
- Invoke-Obfuscation Via Use Clip - Powershell · sigma-rule
- Invoke-Obfuscation Via Use Clip - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Clip - Security · sigma-rule
- Invoke-Obfuscation Via Use Clip - System · sigma-rule
- Invoke-Obfuscation Via Use MSHTA · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - Security · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - System · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - Security · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - System · sigma-rule
- Password Protected ZIP File Opened · sigma-rule
- Password Protected ZIP File Opened (Email Attachment) · sigma-rule
- Password Protected ZIP File Opened (Suspicious Filenames) · sigma-rule
- Ping Hex IP · sigma-rule
- Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image · sigma-rule
- Potential Encoded PowerShell Patterns In CommandLine · sigma-rule
- Potential PowerShell Command Line Obfuscation · sigma-rule
- Potential PowerShell Obfuscation Using Alias Cmdlets · sigma-rule
- Potential PowerShell Obfuscation Using Character Join · sigma-rule
- Potential PowerShell Obfuscation Via Reversed Commands · sigma-rule
- Potential PowerShell Obfuscation Via WCHAR/CHAR · sigma-rule
- Potential Winnti Dropper Activity · sigma-rule
- PowerShell Base64 Encoded Invoke Keyword · sigma-rule
- PowerShell Base64 Encoded Reflective Assembly Load · sigma-rule
- PowerShell Base64 Encoded WMI Classes · sigma-rule
- PUA - Potential PE Metadata Tamper Using Rcedit · sigma-rule
- Renamed AutoIt Execution · sigma-rule
- Suspicious Download Via Certutil.EXE · sigma-rule
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call · sigma-rule
- Suspicious File Downloaded From Direct IP Via Certutil.EXE · sigma-rule
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE · sigma-rule
- Suspicious File Encoded To Base64 Via Certutil.EXE · sigma-rule
- Suspicious Filename with Embedded Base64 Commands · sigma-rule
- Suspicious Get-Variable.exe Creation · sigma-rule
- Suspicious SYSTEM User Process Creation · sigma-rule
- Suspicious XOR Encoded PowerShell Command · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.