1200KM / tag
attack.t1204.002 — sigma-tag tag
27 related reference pages for sigma-tag: attack.t1204.002.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- AppLocker Prevented Application or Script from Running · sigma-rule
- CLR DLL Loaded Via Office Applications · sigma-rule
- DotNET Assembly DLL Loaded Via Office Application · sigma-rule
- Download From Suspicious TLD - Blacklist · sigma-rule
- Download From Suspicious TLD - Whitelist · sigma-rule
- File With Uncommon Extension Created By An Office Application · sigma-rule
- Flash Player Update from Suspicious Location · sigma-rule
- GAC DLL Loaded Via Office Applications · sigma-rule
- HackTool - LittleCorporal Generated Maldoc Injection · sigma-rule
- Microsoft Excel Add-In Loaded From Uncommon Location · sigma-rule
- Microsoft VBA For Outlook Addin Loaded Via Outlook · sigma-rule
- MMC Executing Files with Reversed Extensions Using RTLO Abuse · sigma-rule
- New Application in AppCompat · sigma-rule
- Potential Suspicious Browser Launch From Document Reader Process · sigma-rule
- Remote DLL Load Via Rundll32.EXE · sigma-rule
- Suspicious Binary In User Directory Spawned From Office Application · sigma-rule
- Suspicious LNK Command-Line Padding with Whitespace Characters · sigma-rule
- Suspicious Microsoft Office Child Process · sigma-rule
- Suspicious Microsoft Office Child Process - MacOS · sigma-rule
- Suspicious Outlook Child Process · sigma-rule
- Suspicious Startup Folder Persistence · sigma-rule
- Suspicious WMIC Execution Via Office Process · sigma-rule
- Suspicious WmiPrvSE Child Process · sigma-rule
- VBA DLL Loaded Via Office Application · sigma-rule
- Windows AppX Deployment Full Trust Package Installation · sigma-rule
- Windows AppX Deployment Unsigned Package Installation · sigma-rule
- Windows MSIX Package Support Framework AI_STUBS Execution · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.