1200KM / tag
attack.t1216 — sigma-tag tag
13 related reference pages for sigma-tag: attack.t1216.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Assembly Loading Via CL_LoadAssembly.ps1 · sigma-rule
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl · sigma-rule
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File · sigma-rule
- Execute Code with Pester.bat · sigma-rule
- Execute Code with Pester.bat as Parent · sigma-rule
- Potential Manage-bde.wsf Abuse To Proxy Execution · sigma-rule
- Potential Process Execution Proxy Via CL_Invocation.ps1 · sigma-rule
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1 · sigma-rule
- Remote Code Execute via Winrm.vbs · sigma-rule
- Suspicious CustomShellHost Execution · sigma-rule
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code · sigma-rule
- Uncommon Sigverif.EXE Child Process · sigma-rule
- UtilityFunctions.ps1 Proxy Dll · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.