1200KM / tag
attack.t1036 — sigma-tag tag
38 related reference pages for sigma-tag: attack.t1036.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- CodePage Modification Via MODE.COM To Russian Language · sigma-rule
- CreateDump Process Dump · sigma-rule
- DumpMinitool Execution · sigma-rule
- Explorer Process Tree Break · sigma-rule
- Findstr Launching .lnk File · sigma-rule
- Forfiles.EXE Child Process Masquerading · sigma-rule
- HackTool - XORDump Execution · sigma-rule
- Interactive Bash Suspicious Children · sigma-rule
- New or Renamed User Account with '$' Character · sigma-rule
- New Process Created Via Taskmgr.EXE · sigma-rule
- Password Protected ZIP File Opened (Suspicious Filenames) · sigma-rule
- Potential Command Line Path Traversal Evasion Attempt · sigma-rule
- Potential Fake Instance Of Hxtsr.EXE Executed · sigma-rule
- Potential Homoglyph Attack Using Lookalike Characters · sigma-rule
- Potential Homoglyph Attack Using Lookalike Characters in Filename · sigma-rule
- Potential LSASS Process Dump Via Procdump · sigma-rule
- Potential ReflectDebugger Content Execution Via WerFault.EXE · sigma-rule
- Potential SysInternals ProcDump Evasion · sigma-rule
- Potentially Suspicious Execution From Tmp Folder · sigma-rule
- Procdump Execution · sigma-rule
- Process Execution From A Potentially Suspicious Folder · sigma-rule
- Process Memory Dump Via Comsvcs.DLL · sigma-rule
- PUA - Potential PE Metadata Tamper Using Rcedit · sigma-rule
- Renamed CreateDump Utility Execution · sigma-rule
- Renamed Plink Execution · sigma-rule
- Renamed ZOHO Dctask64 Execution · sigma-rule
- Sdiagnhost Calling Suspicious Child Process · sigma-rule
- Suspicious Calculator Usage · sigma-rule
- Suspicious Child Process Of Wermgr.EXE · sigma-rule
- Suspicious CodePage Switch Via CHCP · sigma-rule
- Suspicious DumpMinitool Execution · sigma-rule
- Suspicious MSDT Parent Process · sigma-rule
- Suspicious Process Parents · sigma-rule
- Suspicious Process Start Locations · sigma-rule
- Suspicious Windows Update Agent Empty Cmdline · sigma-rule
- System File Execution Location Anomaly · sigma-rule
- Taskmgr as LOCAL_SYSTEM · sigma-rule
- Windows Binaries Write Suspicious Extensions · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.