1200KM / tag
attack.t1059.001 — sigma-tag tag
179 related reference pages for sigma-tag: attack.t1059.001.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Alternate PowerShell Hosts - PowerShell Module · sigma-rule
- Alternate PowerShell Hosts Pipe · sigma-rule
- AppLocker Prevented Application or Script from Running · sigma-rule
- AWS EC2 Startup Shell Script Change · sigma-rule
- Bad Opsec Powershell Code Artifacts · sigma-rule
- Base64 Encoded PowerShell Command Detected · sigma-rule
- BloodHound Collection Files · sigma-rule
- Certificate Exported Via PowerShell · sigma-rule
- Change PowerShell Policies to an Insecure Level · sigma-rule
- Change PowerShell Policies to an Insecure Level - PowerShell · sigma-rule
- Cmd.EXE Missing Space Characters Execution Anomaly · sigma-rule
- Command Line Execution with Suspicious URL and AppData Strings · sigma-rule
- ConvertTo-SecureString Cmdlet Usage Via CommandLine · sigma-rule
- Detection of PowerShell Execution via Sqlps.exe · sigma-rule
- DSInternals Suspicious PowerShell Cmdlets · sigma-rule
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock · sigma-rule
- Exchange PowerShell Snap-Ins Usage · sigma-rule
- Execute Code with Pester.bat · sigma-rule
- Execute Code with Pester.bat as Parent · sigma-rule
- Execution of Powershell Script in Public Folder · sigma-rule
- HackTool - Bloodhound/Sharphound Execution · sigma-rule
- HackTool - Covenant PowerShell Launcher · sigma-rule
- HackTool - CrackMapExec Execution · sigma-rule
- HackTool - CrackMapExec Execution Patterns · sigma-rule
- HackTool - CrackMapExec PowerShell Obfuscation · sigma-rule
- HackTool - Default PowerSploit/Empire Scheduled Task Creation · sigma-rule
- HackTool - Empire PowerShell Launch Parameters · sigma-rule
- Hidden Powershell in Link File Pattern · sigma-rule
- HTML Help HH.EXE Suspicious Child Process · sigma-rule
- Import PowerShell Modules From Suspicious Directories · sigma-rule
- Import PowerShell Modules From Suspicious Directories - ProcCreation · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - Security · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - System · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - System · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - Security · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - System · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Powershell · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Security · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR+ Launcher · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - Security · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System · sigma-rule
- Invoke-Obfuscation Via Stdin · sigma-rule
- Invoke-Obfuscation Via Stdin - Powershell · sigma-rule
- Invoke-Obfuscation Via Stdin - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Stdin - Security · sigma-rule
- Invoke-Obfuscation Via Stdin - System · sigma-rule
- Invoke-Obfuscation Via Use Clip · sigma-rule
- Invoke-Obfuscation Via Use Clip - Powershell · sigma-rule
- Invoke-Obfuscation Via Use Clip - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Clip - Security · sigma-rule
- Invoke-Obfuscation Via Use Clip - System · sigma-rule
- Invoke-Obfuscation Via Use MSHTA · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - Security · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - System · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - Security · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - System · sigma-rule
- Malicious Base64 Encoded PowerShell Keywords in Command Lines · sigma-rule
- Malicious Nishang PowerShell Commandlets · sigma-rule
- Malicious PowerShell Commandlets - PoshModule · sigma-rule
- Malicious PowerShell Commandlets - ProcessCreation · sigma-rule
- Malicious PowerShell Commandlets - ScriptBlock · sigma-rule
- Malicious PowerShell Keywords · sigma-rule
- Malicious PowerShell Scripts - FileCreation · sigma-rule
- Malicious PowerShell Scripts - PoshModule · sigma-rule
- Malicious ShellIntel PowerShell Commandlets · sigma-rule
- Net WebClient Casing Anomalies · sigma-rule
- Netcat The Powershell Version · sigma-rule
- New PowerShell Instance Created · sigma-rule
- Non Interactive PowerShell Process Spawned · sigma-rule
- Nslookup PowerShell Download Cradle · sigma-rule
- NTFS Alternate Data Stream · sigma-rule
- Obfuscated PowerShell MSI Install via WindowsInstaller COM · sigma-rule
- Obfuscated PowerShell OneLiner Execution · sigma-rule
- Potential Data Exfiltration Activity Via CommandLine Tools · sigma-rule
- Potential DLL File Download Via PowerShell Invoke-WebRequest · sigma-rule
- Potential Encoded PowerShell Patterns In CommandLine · sigma-rule
- Potential Persistence Via Powershell Search Order Hijacking - Task · sigma-rule
- Potential PowerShell Command Line Obfuscation · sigma-rule
- Potential PowerShell Downgrade Attack · sigma-rule
- Potential PowerShell Obfuscation Using Alias Cmdlets · sigma-rule
- Potential PowerShell Obfuscation Using Character Join · sigma-rule
- Potential PowerShell Obfuscation Via Reversed Commands · sigma-rule
- Potential PowerShell Obfuscation Via WCHAR/CHAR · sigma-rule
- Potential Powershell ReverseShell Connection · sigma-rule
- Potential Remote PowerShell Session Initiated · sigma-rule
- Potential Suspicious PowerShell Keywords · sigma-rule
- Potential WinAPI Calls Via PowerShell Scripts · sigma-rule
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell · sigma-rule
- Potentially Suspicious Command Executed Via Run Dialog Box - Registry · sigma-rule
- Potentially Suspicious Powershell Script Execution From Temp Folder · sigma-rule
- Potentially Suspicious WebDAV LNK Execution · sigma-rule
- PowerShell ADRecon Execution · sigma-rule
- PowerShell Base64 Encoded FromBase64String Cmdlet · sigma-rule
- PowerShell Base64 Encoded IEX Cmdlet · sigma-rule
- PowerShell Base64 Encoded Invoke Keyword · sigma-rule
- PowerShell Base64 Encoded Reflective Assembly Load · sigma-rule
- PowerShell Base64 Encoded WMI Classes · sigma-rule
- PowerShell Called from an Executable Version Mismatch · sigma-rule
- PowerShell Core DLL Loaded By Non PowerShell Process · sigma-rule
- PowerShell Create Local User · sigma-rule
- PowerShell Credential Prompt · sigma-rule
- PowerShell Downgrade Attack - PowerShell · sigma-rule
- PowerShell Download Pattern · sigma-rule
- PowerShell Download Via Net.WebClient - PowerShell Classic · sigma-rule
- Powershell Executed From Headless ConHost Process · sigma-rule
- Powershell Inline Execution From A File · sigma-rule
- PowerShell MSI Install via WindowsInstaller COM From Remote Location · sigma-rule
- Powershell MsXml COM Object · sigma-rule
- PowerShell PSAttack · sigma-rule
- PowerShell Remote Session Creation · sigma-rule
- PowerShell Script Run in AppData · sigma-rule
- PowerShell ShellCode · sigma-rule
- PowerShell Web Access Installation - PsScript · sigma-rule
- Powershell XML Execute Command · sigma-rule
- PowerView PowerShell Cmdlets - ScriptBlock · sigma-rule
- PSAsyncShell - Asynchronous TCP Reverse Shell · sigma-rule
- Remote LSASS Process Access Through Windows Remote Management · sigma-rule
- Remote PowerShell Session (PS Classic) · sigma-rule
- Remote PowerShell Session (PS Module) · sigma-rule
- Remote PowerShell Session Host Process (WinRM) · sigma-rule
- Remote PowerShell Sessions Network Connections (WinRM) · sigma-rule
- Remote Thread Creation Via PowerShell In Uncommon Target · sigma-rule
- Renamed Powershell Under Powershell Channel · sigma-rule
- Scheduled Task Executing Encoded Payload from Registry · sigma-rule
- Scheduled Task Executing Payload from Registry · sigma-rule
- Silence.EDA Detection · sigma-rule
- SQL Client Tools PowerShell Session Detection · sigma-rule
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call · sigma-rule
- Suspicious Encoded PowerShell Command Line · sigma-rule
- Suspicious Execution of Powershell with Base64 · sigma-rule
- Suspicious File Execution From Internet Hosted WebDav Share · sigma-rule
- Suspicious HH.EXE Execution · sigma-rule
- Suspicious Interactive PowerShell as SYSTEM · sigma-rule
- Suspicious Non PowerShell WSMAN COM Provider · sigma-rule
- Suspicious PowerShell Download - PoshModule · sigma-rule
- Suspicious PowerShell Download - Powershell Script · sigma-rule
- Suspicious PowerShell Download and Execute Pattern · sigma-rule
- Suspicious PowerShell Encoded Command Patterns · sigma-rule
- Suspicious PowerShell IEX Execution Patterns · sigma-rule
- Suspicious PowerShell Invocation From Script Engines · sigma-rule
- Suspicious PowerShell Invocations - Generic · sigma-rule
- Suspicious PowerShell Invocations - Generic - PowerShell Module · sigma-rule
- Suspicious PowerShell Invocations - Specific · sigma-rule
- Suspicious PowerShell Invocations - Specific - PowerShell Module · sigma-rule
- Suspicious PowerShell Parameter Substring · sigma-rule
- Suspicious PowerShell Parent Process · sigma-rule
- Suspicious Schtasks Execution AppData Folder · sigma-rule
- Suspicious WSMAN Provider Image Loads · sigma-rule
- Suspicious XOR Encoded PowerShell Command · sigma-rule
- Usage Of Web Request Commands And Cmdlets · sigma-rule
- Usage Of Web Request Commands And Cmdlets - ScriptBlock · sigma-rule
- Windows Shell/Scripting Processes Spawning Suspicious Programs · sigma-rule
- WMImplant Hack Tool · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.