1200KM / tag
attack.t1112 — sigma-tag tag
78 related reference pages for sigma-tag: attack.t1112.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Activate Suppression of Windows Security Center Notifications · sigma-rule
- Add DisallowRun Execution to Registry · sigma-rule
- Allow RDP Remote Assistance Feature · sigma-rule
- Change the Fax Dll · sigma-rule
- Change User Account Associated with the FAX Service · sigma-rule
- ClickOnce Trust Prompt Tampering · sigma-rule
- CrashControl CrashDump Disabled · sigma-rule
- DHCP Callout DLL Installation · sigma-rule
- Disable Internal Tools or Feature in Registry · sigma-rule
- Disable Security Events Logging Adding Reg Key MiniNt · sigma-rule
- Disable Windows Security Center Notifications · sigma-rule
- DNS-over-HTTPS Enabled by Registry · sigma-rule
- Enable LM Hash Storage · sigma-rule
- Enable LM Hash Storage - ProcCreation · sigma-rule
- ETW Logging Disabled For rpcrt4.dll · sigma-rule
- ETW Logging Disabled For SCM · sigma-rule
- ETW Logging Disabled In .NET Processes - Registry · sigma-rule
- ETW Logging Disabled In .NET Processes - Sysmon Registry · sigma-rule
- Imports Registry Key From a File · sigma-rule
- Imports Registry Key From an ADS · sigma-rule
- Macro Enabled In A Potentially Suspicious Document · sigma-rule
- Modification of IE Registry Settings · sigma-rule
- NET NGenAssemblyUsageLog Registry Key Tamper · sigma-rule
- NetNTLM Downgrade Attack · sigma-rule
- NetNTLM Downgrade Attack - Registry · sigma-rule
- New BgInfo.EXE Custom DB Path Registry Configuration · sigma-rule
- New BgInfo.EXE Custom VBScript Registry Configuration · sigma-rule
- New BgInfo.EXE Custom WMI Query Registry Configuration · sigma-rule
- New DNS ServerLevelPluginDll Installed · sigma-rule
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE · sigma-rule
- Non-privileged Usage of Reg or Powershell · sigma-rule
- Office Macros Warning Disabled · sigma-rule
- Outlook EnableUnsafeClientMailRules Setting Enabled - Registry · sigma-rule
- Potential Persistence Via Custom Protocol Handler · sigma-rule
- Potential Persistence Via Event Viewer Events.asp · sigma-rule
- Potential Persistence Via Outlook Home Page · sigma-rule
- Potential Persistence Via Outlook Today Page · sigma-rule
- Potential Qakbot Registry Activity · sigma-rule
- Potential Suspicious Registry File Imported Via Reg.EXE · sigma-rule
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE · sigma-rule
- Potentially Suspicious Desktop Background Change Using Reg.EXE · sigma-rule
- Potentially Suspicious Desktop Background Change Via Registry · sigma-rule
- PowerShell Logging Disabled Via Registry Key Tampering · sigma-rule
- RDP Sensitive Settings Changed · sigma-rule
- RDP Sensitive Settings Changed to Zero · sigma-rule
- RedMimicry Winnti Playbook Registry Manipulation · sigma-rule
- Reg Add Suspicious Paths · sigma-rule
- Registry Entries For Azorult Malware · sigma-rule
- Registry Explorer Policy Modification · sigma-rule
- Registry Hide Function from User · sigma-rule
- Registry Manipulation via WMI Stdregprov · sigma-rule
- Registry Modification Attempt Via VBScript · sigma-rule
- Registry Modification Attempt Via VBScript - PowerShell · sigma-rule
- Registry Modification for OCI DLL Redirection · sigma-rule
- Registry Modification of MS-settings Protocol Handler · sigma-rule
- Registry Modification Via Regini.EXE · sigma-rule
- Registry Tampering by Potentially Suspicious Processes · sigma-rule
- Remote Registry Lateral Movement · sigma-rule
- Removal of Potential COM Hijacking Registry Keys · sigma-rule
- RestrictedAdminMode Registry Value Tampering · sigma-rule
- RestrictedAdminMode Registry Value Tampering - ProcCreation · sigma-rule
- Run Once Task Configuration in Registry · sigma-rule
- Run Once Task Execution as Configured in Registry · sigma-rule
- Security Event Logging Disabled via MiniNt Registry Key - Process · sigma-rule
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set · sigma-rule
- Service Binary in Suspicious Folder · sigma-rule
- ShimCache Flush · sigma-rule
- Suspicious Registry Modification From ADS Via Regini.EXE · sigma-rule
- Suspicious VBoxDrvInst.exe Parameters · sigma-rule
- Sysmon Channel Reference Deletion · sigma-rule
- Terminal Server Client Connection History Cleared - Registry · sigma-rule
- Trust Access Disable For VBApplications · sigma-rule
- Uncommon Microsoft Office Trusted Location Added · sigma-rule
- User Shell Folders Registry Modification via CommandLine · sigma-rule
- Wdigest CredGuard Registry Modification · sigma-rule
- Wdigest Enable UseLogonCredential · sigma-rule
- Windows Event Log Access Tampering Via Registry · sigma-rule
- Winlogon AllowMultipleTSSessions Enable · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.