1200KM / tag
attack.t1055 — sigma-tag tag
24 related reference pages for sigma-tag: attack.t1055.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- CobaltStrike Named Pipe · sigma-rule
- CobaltStrike Named Pipe Pattern Regex · sigma-rule
- CobaltStrike Named Pipe Patterns · sigma-rule
- Created Files by Microsoft Sync Center · sigma-rule
- Dllhost.EXE Execution Anomaly · sigma-rule
- DotNet CLR DLL Loaded By Scripting Applications · sigma-rule
- HackTool - CoercedPotato Execution · sigma-rule
- HackTool - CoercedPotato Named Pipe Creation · sigma-rule
- HackTool - DInjector PowerShell Cradle Execution · sigma-rule
- HackTool - EfsPotato Named Pipe Creation · sigma-rule
- Malicious Named Pipe Created · sigma-rule
- Microsoft Sync Center Suspicious Network Connections · sigma-rule
- Network Connection Initiated Via Notepad.EXE · sigma-rule
- Potential DLL Sideloading Using Coregen.exe · sigma-rule
- Potential Process Injection Via Msra.EXE · sigma-rule
- PowerShell ShellCode · sigma-rule
- Process Creation Using Sysnative Folder · sigma-rule
- Rare Remote Thread Creation By Uncommon Source Image · sigma-rule
- Remote Thread Creation By Uncommon Source Image · sigma-rule
- Suspect Svchost Activity · sigma-rule
- Suspicious Child Process Of Wermgr.EXE · sigma-rule
- Suspicious Rundll32 Invoking Inline VBScript · sigma-rule
- Suspicious Userinit Child Process · sigma-rule
- Uncommon Svchost Command Line Parameter · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.