1200KM / tag
attack.t1218.011 — sigma-tag tag
27 related reference pages for sigma-tag: attack.t1218.011.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments · sigma-rule
- CobaltStrike Load by Rundll32 · sigma-rule
- Code Execution via Pcwutl.dll · sigma-rule
- HackTool - F-Secure C3 Load by Rundll32 · sigma-rule
- HackTool - RedMimicry Winnti Playbook Execution · sigma-rule
- HTML Help HH.EXE Suspicious Child Process · sigma-rule
- Outbound Network Connection To Public IP Via Winlogon · sigma-rule
- Potential PowerShell Execution Via DLL · sigma-rule
- Potentially Suspicious Rundll32 Activity · sigma-rule
- Potentially Suspicious Rundll32.EXE Execution of UDL File · sigma-rule
- Process Access via TrolleyExpress Exclusion · sigma-rule
- Remote Thread Creation Via PowerShell In Uncommon Target · sigma-rule
- Rundll32 Execution With Uncommon DLL Extension · sigma-rule
- Rundll32 InstallScreenSaver Execution · sigma-rule
- Rundll32 Internet Connection · sigma-rule
- RunDLL32 Spawning Explorer · sigma-rule
- Rundll32 UNC Path Execution · sigma-rule
- SCR File Write Event · sigma-rule
- ScreenSaver Registry Key Set · sigma-rule
- Shell32 DLL Execution in Suspicious Directory · sigma-rule
- Suspicious Control Panel DLL Load · sigma-rule
- Suspicious HH.EXE Execution · sigma-rule
- Suspicious Rundll32 Activity Invoking Sys File · sigma-rule
- Suspicious Rundll32 Execution With Image Extension · sigma-rule
- Suspicious Rundll32 Setupapi.dll Activity · sigma-rule
- Suspicious ShellExec_RunDLL Call Via Ordinal · sigma-rule
- Unsigned DLL Loaded by Windows Utility · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.