1200KM / tag
attack.t1078 — sigma-tag tag
55 related reference pages for sigma-tag: attack.t1078.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Account Created And Deleted Within A Close Time Frame · sigma-rule
- Account Tampering - Suspicious Failed Logon Reasons · sigma-rule
- Activity From Anonymous IP Address · sigma-rule
- Application Using Device Code Authentication Flow · sigma-rule
- Applications That Are Using ROPC Authentication Flow · sigma-rule
- Atypical Travel · sigma-rule
- Authentications To Important Apps Using Single Factor Authentication · sigma-rule
- AWS Key Pair Import Activity · sigma-rule
- AWS Suspicious SAML Activity · sigma-rule
- Azure AD Threat Intelligence · sigma-rule
- Azure Domain Federation Settings Modified · sigma-rule
- Azure Kubernetes Admission Controller · sigma-rule
- Azure Login Bypassing Conditional Access Policies · sigma-rule
- Azure Subscription Permission Elevation Via AuditLogs · sigma-rule
- Azure Unusual Authentication Interruption · sigma-rule
- Cisco BGP Authentication Failures · sigma-rule
- Cisco LDP Authentication Failures · sigma-rule
- External Remote RDP Logon from Public IP · sigma-rule
- External Remote SMB Logon from Public IP · sigma-rule
- Failed Logon From Public IP · sigma-rule
- Google Cloud Kubernetes Admission Controller · sigma-rule
- Google Workspace Government Attack Warning · sigma-rule
- Guest Account Enabled Via Sysadminctl · sigma-rule
- Guest Users Invited To Tenant By Non Approved Inviters · sigma-rule
- Huawei BGP Authentication Failures · sigma-rule
- Impossible Travel · sigma-rule
- Increased Failed Authentications Of Any Type · sigma-rule
- Invalid PIM License · sigma-rule
- Juniper BGP Missing MD5 · sigma-rule
- Kubernetes Admission Controller Modification · sigma-rule
- Logon from a Risky IP Address · sigma-rule
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure · sigma-rule
- Measurable Increase Of Successful Authentications · sigma-rule
- Microsoft 365 - Impossible Travel Activity · sigma-rule
- New Country · sigma-rule
- OpenCanary - SSH Login Attempt · sigma-rule
- OpenCanary - SSH New Connection Attempt · sigma-rule
- OpenCanary - Telnet Login Attempt · sigma-rule
- Password Provided In Command Line Of Net.EXE · sigma-rule
- PIM Alert Setting Changes To Disabled · sigma-rule
- Roles Activated Too Frequently · sigma-rule
- Roles Activation Doesn't Require MFA · sigma-rule
- Roles Are Not Being Used · sigma-rule
- Roles Assigned Outside PIM · sigma-rule
- Root Account Enable Via Dsenableroot · sigma-rule
- Stale Accounts In A Privileged Role · sigma-rule
- Suspicious Browser Activity · sigma-rule
- Suspicious Computer Machine Password by PowerShell · sigma-rule
- Suspicious Remote Logon with Explicit Credentials · sigma-rule
- Suspicious SignIns From A Non Registered Device · sigma-rule
- Too Many Global Admins · sigma-rule
- Unfamiliar Sign-In Properties · sigma-rule
- User Added to an Administrator's Azure AD Role · sigma-rule
- User Added to Local Administrator Group · sigma-rule
- Win Susp Computer Name Containing Samtheadmin · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.