1200KM / tag
attack.t1218.010 — sigma-tag tag
17 related reference pages for sigma-tag: attack.t1218.010.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- DNS Query Request By Regsvr32.EXE · sigma-rule
- HTML Help HH.EXE Suspicious Child Process · sigma-rule
- Network Connection Initiated By Regsvr32.EXE · sigma-rule
- Potential Regsvr32 Commandline Flag Anomaly · sigma-rule
- Potentially Suspicious Child Process Of Regsvr32 · sigma-rule
- Potentially Suspicious Regsvr32 HTTP IP Pattern · sigma-rule
- Potentially Suspicious Regsvr32 HTTP/FTP Pattern · sigma-rule
- Regsvr32 DLL Execution With Suspicious File Extension · sigma-rule
- Regsvr32 Execution From Highly Suspicious Location · sigma-rule
- Regsvr32 Execution From Potential Suspicious Location · sigma-rule
- Scripting/CommandLine Process Spawned Regsvr32 · sigma-rule
- Suspicious HH.EXE Execution · sigma-rule
- Suspicious Microsoft Office Child Process · sigma-rule
- Suspicious Regsvr32 Execution From Remote Share · sigma-rule
- Suspicious WMIC Execution Via Office Process · sigma-rule
- Suspicious WmiPrvSE Child Process · sigma-rule
- Unsigned DLL Loaded by Windows Utility · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.