1200KM / tag
attack.t1127 — sigma-tag tag
19 related reference pages for sigma-tag: attack.t1127.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- AspNetCompiler Execution · sigma-rule
- C# IL Code Compilation Via Ilasm.EXE · sigma-rule
- Detection of PowerShell Execution via Sqlps.exe · sigma-rule
- JScript Compiler Execution · sigma-rule
- Kavremover Dropped Binary LOLBIN Usage · sigma-rule
- Node Process Executions · sigma-rule
- Potential Arbitrary Code Execution Via Node.EXE · sigma-rule
- Potential Binary Proxy Execution Via Cdb.EXE · sigma-rule
- Potential Mftrace.EXE Abuse · sigma-rule
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler · sigma-rule
- Remote Thread Creation Ttdinject.exe Proxy · sigma-rule
- SQL Client Tools PowerShell Session Detection · sigma-rule
- Suspicious Child Process of AspNetCompiler · sigma-rule
- Suspicious File Created by ArcSOC.exe · sigma-rule
- Suspicious Use of CSharp Interactive Console · sigma-rule
- Use of Remote.exe · sigma-rule
- Use of TTDInject.exe · sigma-rule
- Use of VSIISExeLauncher.exe · sigma-rule
- Use of Wfc.exe · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.