1200KM / tag
attack.t1105 — sigma-tag tag
70 related reference pages for sigma-tag: attack.t1105.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- AppX Package Installation Attempts Via AppInstaller.EXE · sigma-rule
- Arbitrary File Download Via GfxDownloadWrapper.EXE · sigma-rule
- Browser Execution In Headless Mode · sigma-rule
- Cisco Stage Data · sigma-rule
- Command Line Execution with Suspicious URL and AppData Strings · sigma-rule
- Curl Download And Execute Combination · sigma-rule
- Curl Usage on Linux · sigma-rule
- Download File To Potentially Suspicious Directory Via Wget · sigma-rule
- Download from Suspicious Dyndns Hosts · sigma-rule
- Executable from Webdav · sigma-rule
- File Download And Execution Via IEExec.EXE · sigma-rule
- File Download From Browser Process Via Inline URL · sigma-rule
- File Download From IP Based URL Via CertOC.EXE · sigma-rule
- File Download Using Notepad++ GUP Utility · sigma-rule
- File Download Via Bitsadmin · sigma-rule
- File Download Via Bitsadmin To A Suspicious Target Folder · sigma-rule
- File Download via CertOC.EXE · sigma-rule
- File Download Via Nscurl - MacOS · sigma-rule
- File Download Via Windows Defender MpCmpRun.EXE · sigma-rule
- File Download with Headless Browser · sigma-rule
- File With Suspicious Extension Downloaded Via Bitsadmin · sigma-rule
- Finger.EXE Execution · sigma-rule
- Hidden Flag Set On File/Directory Via Chflags - MacOS · sigma-rule
- Import LDAP Data Interchange Format File Via Ldifde.EXE · sigma-rule
- Insensitive Subfolder Search Via Findstr.EXE · sigma-rule
- Legitimate Application Writing Files In Uncommon Location · sigma-rule
- Local Network Connection Initiated By Script Interpreter · sigma-rule
- Lolbas OneDriveStandaloneUpdater.exe Proxy Download · sigma-rule
- MsiExec Web Install · sigma-rule
- Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder · sigma-rule
- Network Connection Initiated By IMEWDBLD.EXE · sigma-rule
- Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location · sigma-rule
- Outbound Network Connection Initiated By Script Interpreter · sigma-rule
- Password Protected ZIP File Opened (Suspicious Filenames) · sigma-rule
- Potential COM Objects Download Cradles Usage - Process Creation · sigma-rule
- Potential COM Objects Download Cradles Usage - PS Script · sigma-rule
- Potential DLL File Download Via PowerShell Invoke-WebRequest · sigma-rule
- Potential Download/Upload Activity Using Type Command · sigma-rule
- Potential In-Memory Download And Compile Of Payloads · sigma-rule
- Potentially Suspicious File Creation by OpenEDR's ITSMService · sigma-rule
- PowerShell Download Via Net.WebClient - PowerShell Classic · sigma-rule
- PowerShell MSI Install via WindowsInstaller COM From Remote Location · sigma-rule
- PrintBrm ZIP Creation of Extraction · sigma-rule
- PUA - Nimgrab Execution · sigma-rule
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server · sigma-rule
- Remote File Copy · sigma-rule
- Remote File Download Via Desktopimgdownldr Utility · sigma-rule
- Remote File Download Via Findstr.EXE · sigma-rule
- Replace.exe Usage · sigma-rule
- Scheduled Task Creation with Curl and PowerShell Execution Combo · sigma-rule
- Suspicious CertReq Command to Download · sigma-rule
- Suspicious Curl File Upload - Linux · sigma-rule
- Suspicious Curl.EXE Download · sigma-rule
- Suspicious Deno File Written from Remote Source · sigma-rule
- Suspicious Desktopimgdownldr Command · sigma-rule
- Suspicious Desktopimgdownldr Target File · sigma-rule
- Suspicious Diantz Download and Compress Into a CAB File · sigma-rule
- Suspicious Download From File-Sharing Website Via Bitsadmin · sigma-rule
- Suspicious Download from Office Domain · sigma-rule
- Suspicious Download Via Certutil.EXE · sigma-rule
- Suspicious Dropbox API Usage · sigma-rule
- Suspicious Extrac32 Execution · sigma-rule
- Suspicious File Created by ArcSOC.exe · sigma-rule
- Suspicious File Downloaded From Direct IP Via Certutil.EXE · sigma-rule
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE · sigma-rule
- Suspicious Invoke-WebRequest Execution · sigma-rule
- Suspicious Invoke-WebRequest Execution With DirectIP · sigma-rule
- Suspicious Non-Browser Network Communication With Telegram API · sigma-rule
- Uncommon Network Connection Initiated By Certutil.EXE · sigma-rule
- Wget Creating Files in Tmp Directory · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.