1200KM / tag
attack.t1219.002 — sigma-tag tag
41 related reference pages for sigma-tag: attack.t1219.002.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Antivirus Exploitation Framework Detection · sigma-rule
- Anydesk Temporary Artefact · sigma-rule
- Atera Agent Installation · sigma-rule
- DNS Query To AzureWebsites.NET By Non-Browser Process · sigma-rule
- DNS Query To Remote Access Software Domain From Non-Browser App · sigma-rule
- GoToAssist Temporary Installation Artefact · sigma-rule
- HackTool - Inveigh Execution Artefacts · sigma-rule
- HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators · sigma-rule
- Hijack Legit RDP Session to Move Laterally · sigma-rule
- Installation of TeamViewer Desktop · sigma-rule
- Mesh Agent Service Installation · sigma-rule
- Mstsc.EXE Execution With Local RDP File · sigma-rule
- Potential Amazon SSM Agent Hijacking · sigma-rule
- Potential Linux Amazon SSM Agent Hijacking · sigma-rule
- Potential Remote Desktop Connection to Non-Domain Host · sigma-rule
- QuickAssist Execution · sigma-rule
- Remote Access Tool - AnyDesk Execution · sigma-rule
- Remote Access Tool - Anydesk Execution From Suspicious Folder · sigma-rule
- Remote Access Tool - AnyDesk Incoming Connection · sigma-rule
- Remote Access Tool - AnyDesk Piped Password Via CLI · sigma-rule
- Remote Access Tool - AnyDesk Silent Installation · sigma-rule
- Remote Access Tool - GoToAssist Execution · sigma-rule
- Remote Access Tool - LogMeIn Execution · sigma-rule
- Remote Access Tool - MeshAgent Command Execution via MeshCentral · sigma-rule
- Remote Access Tool - NetSupport Execution · sigma-rule
- Remote Access Tool - Potential MeshAgent Execution - MacOS · sigma-rule
- Remote Access Tool - Potential MeshAgent Execution - Windows · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - MacOS · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - Windows · sigma-rule
- Remote Access Tool - ScreenConnect Execution · sigma-rule
- Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution · sigma-rule
- Remote Access Tool - Simple Help Execution · sigma-rule
- Remote Access Tool - UltraViewer Execution · sigma-rule
- ScreenConnect Temporary Installation Artefact · sigma-rule
- Suspicious Binary Writes Via AnyDesk · sigma-rule
- Suspicious Mstsc.EXE Execution With Local RDP File · sigma-rule
- Suspicious TSCON Start as SYSTEM · sigma-rule
- TacticalRMM Service Installation · sigma-rule
- TeamViewer Domain Query By Non-TeamViewer Application · sigma-rule
- TeamViewer Remote Session · sigma-rule
- Use of UltraVNC Remote Access Software · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.