1200KM / tag
attack.t1087 — sigma-tag tag
15 related reference pages for sigma-tag: attack.t1087.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Chopper Webshell Process Pattern · sigma-rule
- HackTool - SOAPHound Execution · sigma-rule
- HackTool - winPEAS Execution · sigma-rule
- Hacktool Ruler · sigma-rule
- Malicious PowerShell Commandlets - PoshModule · sigma-rule
- Malicious PowerShell Commandlets - ProcessCreation · sigma-rule
- Malicious PowerShell Commandlets - ScriptBlock · sigma-rule
- Network Reconnaissance Activity · sigma-rule
- Potentially Suspicious EventLog Recon Activity Using Log Query Utilities · sigma-rule
- PUA - Seatbelt Execution · sigma-rule
- SharpHound Recon Account Discovery · sigma-rule
- Suspicious Use of PsLogList · sigma-rule
- Uncommon Connection to Active Directory Web Services · sigma-rule
- Webshell Detection With Command Line Keywords · sigma-rule
- Webshell Hacking Activity Patterns · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.