Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| ActiveMalwareEnergy | Dan Goodin. (2014, June 30). Active malware operation let attackers sabotage US energy industry. Retrieved March 9, 2017. |
| AdSecurity Cracking Kerberos Dec 2015 | Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018. |
| AdSecurity Forging Trust Tickets | Metcalf, S. (2015, July 15). It’s All About Trust – Forging Kerberos Trust Tickets to Spoof Access across Active Directory Trusts. Retrieved February 14, 2019. |
| AdSecurity Kerberos GT Aug 2015 | Metcalf, S. (2015, August 7). Kerberos Golden Tickets are Now More Golden. Retrieved December 1, 2017. |
| Add List Remove Login Items Apple Script | kaloprominat. (2013, July 30). macos: manage add list remove login items apple script. Retrieved October 5, 2021. |
| AddMonitor | Microsoft. (n.d.). AddMonitor function. Retrieved September 12, 2024. |
| Adding Login Items | Apple. (2016, September 13). Adding Login Items. Retrieved July 11, 2017. |
| Adlice Software IAT Hooks Oct 2014 | Tigzy. (2014, October 15). Userland Rootkits: Part 1, IAT hooks. Retrieved December 12, 2017. |
| Adsecurity Mimikatz Guide | Metcalf, S. (2015, November 13). Unofficial Guide to Mimikatz & Command Reference. Retrieved December 23, 2015. |
| Adventures of a Keystroke | Tinaztepe, E. (n.d.). The Adventures of a Keystroke: An in-depth look into keyloggers on Windows. Retrieved April 27, 2016. |
| Ahmed Backdoors in Python and NPM Packages | Deeba Ahmed. (2025, June 2). Backdoors in Python and NPM Packages Target Windows and Linux. Retrieved September 24, 2025. |
| Ahn Lab CoinMiner 2023 | Ahn Lab. (2023, April 24). CoinMiner (KONO DIO DA) Distributed to Linux SSH Servers. Retrieved April 4, 2025. |
| AhnLab Andariel Subgroup of Lazarus June 2018 | AhnLab. (2018, June 23). Targeted attacks by Andariel Threat Group, a subgroup of the Lazarus. Retrieved September 29, 2021. |
| AhnLab Kimsuky Kabar Cobra Feb 2019 | AhnLab. (2019, February 28). Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group. Retrieved September 29, 2021. |
| AhnLab LummaC2 2025 | AhnLab SEcurity intelligence Center. (2025, January 8). Infostealer LummaC2 Spreading Through Fake CAPTCHA Verification Page. Retrieved April 23, 2025. |
| AhnLab Malicioys Copy Paste 2024 | AhnLab SEcurity intelligence Center. (2024, May 23). Warning Against Phishing Emails Prompting Execution of Commands via Paste (CTRL+V). Retrieved April 23, 2025. |
| AhnLab_SystemBC_Apr2022 | AhnLab. (2022, April 4). SystemBC Being Used by Various Attackers . Retrieved June 18, 2025. |
| Aikido CanisterWorm MAR 2026 | Eriksen, C. (2026, March 22). CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran. Retrieved July 27, 2026. |
| Aikido GlassWorm October 2025 | Ilyas Makari. (2025, October 31). The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties. Retrieved April 10, 2026. |
| Aikido Shai-Hulud September 2025 | Charlie Eriksen. (2025, September 16). S1ngularity/nx attackers strike again. Retrieved April 9, 2026. |
| Aikido TeamPCP Telnyx MAR 2026 | Eriksen, C. (2026, March 27). Popular telnyx package compromised on PyPI by TeamPCP. Retrieved July 16, 2026. |
| Aikido TeamPCP Trivy MAR 2026 | Eriksen, C. (2026, March 20). TeamPCP deploys CanisterWorm on NPM following Trivy compromise. Retrieved July 27, 2026. |
| Airbus Derusbi 2015 | Perigaud, F. (2015, December 15). Newcomers in the Derusbi family. Retrieved September 12, 2024. |
| Airbus Security Kovter Analysis | Dove, A. (2016, March 23). Fileless Malware – A Behavioural Analysis Of Kovter Persistence. Retrieved December 5, 2017. |
| Akamai DGA Mitigation | Liu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019. |
| Akamai JS | Katz, O. (2020, October 26). Catch Me if You Can—JavaScript Obfuscation. Retrieved March 17, 2023. |
| Akami Frog4Shell 2024 | Ori David. (2024, February 1). Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal. Retrieved September 24, 2024. |
| AlKhaser Debug | Noteworthy. (2019, January 6). Al-Khaser. Retrieved April 1, 2022. |
| Aleks Weapons Nov 2015 | Nick Aleks. (2015, November 7). Weapons of a Pentester - Understanding the virtual & physical tools used by white/black hat hackers. Retrieved March 30, 2018. |
| Alexa-dns | Scanning Alexa's Top 1M for AXFR. (2015, March 29). Retrieved June 5, 2024. |
| AlienVault Sykipot 2011 | Blasco, J. (2011, December 12). Another Sykipot sample likely targeting US federal agencies. Retrieved March 28, 2016. |
| Alienvault Sykipot DOD Smart Cards | Blasco, J. (2012, January 12). Sykipot variant hijacks DOD and Windows smart cards. Retrieved January 10, 2016. |
| Alintanahin 2014 | Alintanahin, K. (2014, March 13). Kunming Attack Leads to Gh0st RAT Variant. Retrieved November 12, 2014. |
| Almond COR_PROFILER Apr 2019 | Almond. (2019, April 30). UAC bypass via elevated .NET applications. Retrieved June 24, 2020. |
| Alperovitch 2014 | Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014. |
| Alperovitch Malware | Alperovitch, D. (2014, October 31). Malware-Free Intrusions. Retrieved November 17, 2024. |
| Amazon AWS VPC Guide | Amazon. (n.d.). What Is Amazon VPC?. Retrieved October 6, 2019. |
| Amazon Describe Instance | Amazon. (n.d.). describe-instance-information. Retrieved March 3, 2020. |
| Amazon Describe Instances API | Amazon. (n.d.). DescribeInstances. Retrieved May 26, 2020. |
| Amazon S3 Security, 2019 | Amazon. (2019, May 17). How can I secure the files in my Amazon S3 bucket?. Retrieved October 4, 2019. |
| Amnesty Intl. Ocean Lotus February 2021 | Amnesty International. (2021, February 24). Vietnamese activists targeted by notorious hacking group. Retrieved March 1, 2021. |
| Amnesty OAuth Phishing Attacks, August 2019 | Amnesty International. (2019, August 16). Evolving Phishing Attacks Targeting Journalists and Human Rights Defenders from the Middle-East and North Africa. Retrieved October 8, 2019. |
| Amplia WCE | Amplia Security. (n.d.). Windows Credentials Editor (WCE) F.A.Q.. Retrieved September 12, 2024. |
| Anatomy of an hVNC Attack | Keshet, Lior. Kessem, Limor. (2017, January 25). Anatomy of an hVNC Attack. Retrieved November 28, 2023. |
| Anomali Evasive Maneuvers July 2015 | Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018. |
| Anomali Linux Rabbit 2018 | Anomali Labs. (2018, December 6). Pulling Linux Rabbit/Rabbot Malware Out of a Hat. Retrieved March 4, 2019. |
| Anomali MUSTANG PANDA October 2019 | Anomali Threat Research. (2019, October 7). China-Based APT Mustang Panda Targets Minority Groups, Public and Private Sector Organizations. Retrieved April 12, 2021. |
| Anomali Pirate Panda April 2020 | Moore, S. et al. (2020, April 30). Anomali Suspects that China-Backed APT Pirate Panda May Be Seeking Access to Vietnam Government Data Center. Retrieved May 19, 2020. |
| Anomali Rocke March 2019 | Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019. |
| Anomali Static Kitten February 2021 | Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.