1200KM / tag
attack.t1552.001 — sigma-tag tag
20 related reference pages for sigma-tag: attack.t1552.001.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Automated Collection Command Prompt · sigma-rule
- Azure Key Vault Modified or Deleted · sigma-rule
- Azure Keyvault Key Modified or Deleted · sigma-rule
- Azure Keyvault Secrets Modified or Deleted · sigma-rule
- Cisco Collect Data · sigma-rule
- Copy Passwd Or Shadow From TMP Path · sigma-rule
- Credentials In Files · sigma-rule
- Credentials In Files - Linux · sigma-rule
- Extracting Information with PowerShell · sigma-rule
- HackTool - Typical HiveNightmare SAM File Export · sigma-rule
- HackTool - WinPwn Execution · sigma-rule
- HackTool - WinPwn Execution - ScriptBlock · sigma-rule
- Hidden Flag Set On File/Directory Via Chflags - MacOS · sigma-rule
- Insensitive Subfolder Search Via Findstr.EXE · sigma-rule
- Linux Recon Indicators · sigma-rule
- Potential PowerShell Console History Access Attempt via History File · sigma-rule
- Potentially Suspicious JWT Token Search Via CLI · sigma-rule
- PUA - TruffleHog Execution · sigma-rule
- PUA - TruffleHog Execution - Linux · sigma-rule
- Remote File Download Via Findstr.EXE · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.