1200KM / tag
attack.t1140 — sigma-tag tag
14 related reference pages for sigma-tag: attack.t1140.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Base64 Encoded PowerShell Command Detected · sigma-rule
- DNS-over-HTTPS Enabled by Registry · sigma-rule
- Linux Base64 Encoded Pipe to Shell · sigma-rule
- Linux Base64 Encoded Shebang In CLI · sigma-rule
- Linux Shell Pipe to Shell · sigma-rule
- MSHTA Execution with Suspicious File Extensions · sigma-rule
- Payload Decoded and Decrypted via Built-in Utilities · sigma-rule
- Ping Hex IP · sigma-rule
- Potential Base64 Decoded From Images · sigma-rule
- Potential Commandline Obfuscation Using Escape Characters · sigma-rule
- PowerShell Base64 Encoded FromBase64String Cmdlet · sigma-rule
- PowerShell Decompress Commands · sigma-rule
- Suspicious Inbox Manipulation Rules · sigma-rule
- Suspicious XOR Encoded PowerShell Command · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.