ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Haq 2014Haq, T., Moran, N., Scott, M., & Vashisht, S. O. (2014, September 10). The Path to Mass-Producing Cyber Attacks [Blog]. Retrieved November 12, 2014.
Harmj0y Abusing GPO PermissionsSchroeder, W. (2016, March 17). Abusing GPO Permissions. Retrieved September 23, 2024.
Harmj0y DCSync Sept 2015Schroeder, W. (2015, September 22). Mimikatz and DCSync and ExtraSids, Oh My. Retrieved December 4, 2017.
Harmj0y Domain TrustsSchroeder, W. (2017, October 30). A Guide to Attacking Domain Trusts. Retrieved February 14, 2019.
Harmj0y Kerberoast Nov 2016Schroeder, W. (2016, November 1). Kerberoasting Without Mimikatz. Retrieved September 23, 2024.
Harmj0y Mimikatz and DCSyncSchroeder, W. (2015, September 22). Mimikatz and DCSync and ExtraSids, Oh My. Retrieved September 23, 2024.
Harmj0y Roasting AS-REPs Jan 2017HarmJ0y. (2017, January 17). Roasting AS-REPs. Retrieved September 23, 2024.
Harmj0y SeEnableDelegationPrivilege RightSchroeder, W. (2017, January 10). The Most Dangerous User Right You (Probably) Have Never Heard Of. Retrieved September 23, 2024.
HarmonProofpoint_SystemBC_Aug2019Harmon, K., et al. (2019, August 1). SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits . Retrieved June 13, 2025.
Hartrell cd00r 2002Hartrell, Greg. (2002, August). Get a handle on cd00r: The invisible backdoor. Retrieved October 13, 2018.
Havana authentication bugJay Pipes. (2013, December 23). Security Breach! Tenant A is seeing the VNC Consoles of Tenant B!. Retrieved September 12, 2024.
Havoc Framework DocumentationUngur, P. (n.d.). HAVOC. Retrieved August 4, 2025.
Help eliminate unquoted pathMark Baggett. (2012, November 8). Help eliminate unquoted path vulnerabilities. Retrieved November 8, 2012.
Hexacorn DLL HijackingHexacorn. (2013, December 8). Beyond good ol’ Run key, Part 5. Retrieved August 14, 2024.
Hexacorn ListplantingHexacorn. (2019, April 25). Listplanting – yet another code injection trick. Retrieved August 14, 2024.
Hexacorn Logon ScriptsHexacorn. (2014, November 14). Beyond good ol’ Run key, Part 18. Retrieved November 15, 2019.
Hexacorn Office Template MacrosHexacorn. (2017, April 17). Beyond good ol’ Run key, Part 62. Retrieved July 3, 2017.
Hexacorn Office TestHexacorn. (2014, April 16). Beyond good ol’ Run key, Part 10. Retrieved July 3, 2017.
Hidden VNCHutchins, Marcus. (2015, September 13). Hidden VNC for Beginners. Retrieved November 28, 2023.
Hide GDM User AccountsJi Mingkui. (2021, June 17). How to Hide All The User Accounts in Ubuntu 20.04, 21.04 Login Screen. Retrieved March 15, 2022.
Hiding Malicious Code with Module StompingAliz Hammond. (2019, August 15). Hiding Malicious Code with "Module Stomping": Part 1. Retrieved July 14, 2022.
HighTech Bridge Inline Hooking Sept 2011Mariani, B. (2011, September 6). Inline Hooking in Windows. Retrieved November 17, 2024.
Hijack DLLs CrowdStrike falcon.overwatch.team. (2022, December 30). 4 Ways Adversaries Hijack DLLs — and How CrowdStrike Falcon OverWatch Fights Back. Retrieved January 30, 2025.
Hijacking VNCZ3RO. (2019, March 10). Day 70: Hijacking VNC (Enum, Brute, Access and Crack). Retrieved September 20, 2021.
Hornet Security Avaddon June 2020Security Lab. (2020, June 5). Avaddon: From seeking affiliates to in-the-wild in 2 days. Retrieved August 19, 2021.
Hunt Sea Turtle 2024Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.
Hunt.io TeamPCP Toolkit MAY 2026Hunt.io. (2026, May 14). How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account. Retrieved July 16, 2026.
Hunters Domain Wide Delegation Google Workspace 2023Yonatan Khanashvilli. (2023, November 28). DeleFriend: Severe design flaw in Domain Wide Delegation could leave Google Workspace vulnerable for takeover. Retrieved January 16, 2024.
Huntio_GamaredonFlux_Apr2025Hunt.io. (2025, April 8). State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure. Retrieved July 23, 2025.
Huntio_IranInfra_Mar2026Hunt.io. (2026, March 4). Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation. Retrieved April 16, 2026.
Huntress API HashBrennan, M. (2022, February 16). Hackers No Hashing: Randomizing API Hashes to Evade Cobalt Strike Shellcode Detection. Retrieved August 22, 2022.
Huntress HTML Smuggling 2024Matt Kiely. (2024, July 5). Smuggler’s Gambit: Uncovering HTML Smuggling Adversary in the Middle Tradecraft. Retrieved March 18, 2025.
Huntress INC Ransom Group August 2023Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Huntress INC Ransomware May 2024Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Huntress Kali365 Device Code June 2026Tanner Flip. (2026, June 11). Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit. Retrieved July 30, 2026.
Huntress LightSpy macOS 2024Stuart Ashenbrenner, Alden Schmidt. (2024, April 25). LightSpy Malware Variant Targeting macOS. Retrieved January 3, 2025.
Huntress MOVEit 2023John Hammond. (2023, June 1). MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response. Retrieved August 5, 2024.
Huntress NPPSPY 2022Dray Agha. (2022, August 16). Cleartext Shenanigans: Gifting User Passwords to Adversaries With NPPSPY. Retrieved May 17, 2024.
Huntress Persistence Microsoft 365 Compromise 2024Sharon Martin. (2024, November 5). Legitimate Apps as Traitorware for Persistent Microsoft 365 Compromise. Retrieved March 20, 2025.
Huntress Python Malware 2025Matthew Brennan. (2024, July 5). Snakes on a Domain: An Analysis of a Python Malware Loader. Retrieved April 3, 2025.
Hybrid Analysis Icacls1 June 2018Hybrid Analysis. (2018, June 12). c9b65b764985dfd7a11d3faf599c56b8.exe. Retrieved August 19, 2018.
Hybrid Analysis Icacls2 May 2018Hybrid Analysis. (2018, May 30). 2a8efbfadd798f6111340f7c1c956bee.dll. Retrieved August 19, 2018.
IAPPIAPP. (n.d.). Retrieved March 5, 2024.
IBM AI-Generated ContentTim Mucci. (n.d.). What is AI-Generated Content?. Retrieved April 22, 2026.
IBM Grandoreiro April 2020Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.
IBM ITG07 June 2019McMillen, D. Sperry, C. (2019, June 14). Observations of ITG07 Cyber Operations. Retrieved May 17, 2021.
IBM ITG18 2020Wikoff, A. Emerson, R. (2020, July 16). New Research Exposes Iranian Threat Group Operations. Retrieved March 8, 2021.
IBM IcedID November 2017Kessem, L., et al. (2017, November 13). New Banking Trojan IcedID Discovered by IBM X-Force Research. Retrieved July 14, 2020.
IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Golo Muhr, Joshua Chung. (2025, June 23). Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor. Retrieved August 4, 2025.
IBM MegaCortexDel Fierro, C. Kessem, L.. (2020, January 8). From Mega to Giga: Cross-Version Comparison of Top MegaCortex Modifications. Retrieved February 15, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.