1200KM / tag
attack.t1106 — sigma-tag tag
11 related reference pages for sigma-tag: attack.t1106.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- BPFDoor Abnormal Process ID or Lock File Accessed · sigma-rule
- HackTool - CobaltStrike BOF Injection Pattern · sigma-rule
- HackTool - HandleKatz Duplicating LSASS Handle · sigma-rule
- HackTool - RedMimicry Winnti Playbook Execution · sigma-rule
- HackTool - WinPwn Execution · sigma-rule
- HackTool - WinPwn Execution - ScriptBlock · sigma-rule
- Potential Binary Proxy Execution Via Cdb.EXE · sigma-rule
- Potential Direct Syscall of NtOpenProcess · sigma-rule
- Potential WinAPI Calls Via CommandLine · sigma-rule
- Potential WinAPI Calls Via PowerShell Scripts · sigma-rule
- Suspicious Mshta.EXE Execution Patterns · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.