ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
ActiveMalwareEnergyDan Goodin. (2014, June 30). Active malware operation let attackers sabotage US energy industry. Retrieved March 9, 2017.
AdSecurity Cracking Kerberos Dec 2015Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.
AdSecurity Forging Trust TicketsMetcalf, S. (2015, July 15). It’s All About Trust – Forging Kerberos Trust Tickets to Spoof Access across Active Directory Trusts. Retrieved February 14, 2019.
AdSecurity Kerberos GT Aug 2015Metcalf, S. (2015, August 7). Kerberos Golden Tickets are Now More Golden. Retrieved December 1, 2017.
Add List Remove Login Items Apple Scriptkaloprominat. (2013, July 30). macos: manage add list remove login items apple script. Retrieved October 5, 2021.
AddMonitorMicrosoft. (n.d.). AddMonitor function. Retrieved September 12, 2024.
Adding Login ItemsApple. (2016, September 13). Adding Login Items. Retrieved July 11, 2017.
Adlice Software IAT Hooks Oct 2014Tigzy. (2014, October 15). Userland Rootkits: Part 1, IAT hooks. Retrieved December 12, 2017.
Adsecurity Mimikatz GuideMetcalf, S. (2015, November 13). Unofficial Guide to Mimikatz & Command Reference. Retrieved December 23, 2015.
Adventures of a KeystrokeTinaztepe, E. (n.d.). The Adventures of a Keystroke: An in-depth look into keyloggers on Windows. Retrieved April 27, 2016.
Ahmed Backdoors in Python and NPM PackagesDeeba Ahmed. (2025, June 2). Backdoors in Python and NPM Packages Target Windows and Linux. Retrieved September 24, 2025.
Ahn Lab CoinMiner 2023Ahn Lab. (2023, April 24). CoinMiner (KONO DIO DA) Distributed to Linux SSH Servers. Retrieved April 4, 2025.
AhnLab Andariel Subgroup of Lazarus June 2018AhnLab. (2018, June 23). Targeted attacks by Andariel Threat Group, a subgroup of the Lazarus. Retrieved September 29, 2021.
AhnLab Kimsuky Kabar Cobra Feb 2019AhnLab. (2019, February 28). Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group. Retrieved September 29, 2021.
AhnLab LummaC2 2025AhnLab SEcurity intelligence Center. (2025, January 8). Infostealer LummaC2 Spreading Through Fake CAPTCHA Verification Page. Retrieved April 23, 2025.
AhnLab Malicioys Copy Paste 2024AhnLab SEcurity intelligence Center. (2024, May 23). Warning Against Phishing Emails Prompting Execution of Commands via Paste (CTRL+V). Retrieved April 23, 2025.
AhnLab_SystemBC_Apr2022AhnLab. (2022, April 4). SystemBC Being Used by Various Attackers . Retrieved June 18, 2025.
Aikido CanisterWorm MAR 2026Eriksen, C. (2026, March 22). CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran. Retrieved July 27, 2026.
Aikido GlassWorm October 2025Ilyas Makari. (2025, October 31). The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties. Retrieved April 10, 2026.
Aikido Shai-Hulud September 2025Charlie Eriksen. (2025, September 16). S1ngularity/nx attackers strike again. Retrieved April 9, 2026.
Aikido TeamPCP Telnyx MAR 2026Eriksen, C. (2026, March 27). Popular telnyx package compromised on PyPI by TeamPCP. Retrieved July 16, 2026.
Aikido TeamPCP Trivy MAR 2026Eriksen, C. (2026, March 20). TeamPCP deploys CanisterWorm on NPM following Trivy compromise. Retrieved July 27, 2026.
Airbus Derusbi 2015Perigaud, F. (2015, December 15). Newcomers in the Derusbi family. Retrieved September 12, 2024.
Airbus Security Kovter AnalysisDove, A. (2016, March 23). Fileless Malware – A Behavioural Analysis Of Kovter Persistence. Retrieved December 5, 2017.
Akamai DGA MitigationLiu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019.
Akamai JSKatz, O. (2020, October 26). Catch Me if You Can—JavaScript Obfuscation. Retrieved March 17, 2023.
Akami Frog4Shell 2024Ori David. (2024, February 1). Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal. Retrieved September 24, 2024.
AlKhaser DebugNoteworthy. (2019, January 6). Al-Khaser. Retrieved April 1, 2022.
Aleks Weapons Nov 2015Nick Aleks. (2015, November 7). Weapons of a Pentester - Understanding the virtual & physical tools used by white/black hat hackers. Retrieved March 30, 2018.
Alexa-dnsScanning Alexa's Top 1M for AXFR. (2015, March 29). Retrieved June 5, 2024.
AlienVault Sykipot 2011Blasco, J. (2011, December 12). Another Sykipot sample likely targeting US federal agencies. Retrieved March 28, 2016.
Alienvault Sykipot DOD Smart CardsBlasco, J. (2012, January 12). Sykipot variant hijacks DOD and Windows smart cards. Retrieved January 10, 2016.
Alintanahin 2014Alintanahin, K. (2014, March 13). Kunming Attack Leads to Gh0st RAT Variant. Retrieved November 12, 2014.
Almond COR_PROFILER Apr 2019Almond. (2019, April 30). UAC bypass via elevated .NET applications. Retrieved June 24, 2020.
Alperovitch 2014Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.
Alperovitch MalwareAlperovitch, D. (2014, October 31). Malware-Free Intrusions. Retrieved November 17, 2024.
Amazon AWS VPC GuideAmazon. (n.d.). What Is Amazon VPC?. Retrieved October 6, 2019.
Amazon Describe InstanceAmazon. (n.d.). describe-instance-information. Retrieved March 3, 2020.
Amazon Describe Instances APIAmazon. (n.d.). DescribeInstances. Retrieved May 26, 2020.
Amazon S3 Security, 2019Amazon. (2019, May 17). How can I secure the files in my Amazon S3 bucket?. Retrieved October 4, 2019.
Amnesty Intl. Ocean Lotus February 2021Amnesty International. (2021, February 24). Vietnamese activists targeted by notorious hacking group. Retrieved March 1, 2021.
Amnesty OAuth Phishing Attacks, August 2019Amnesty International. (2019, August 16). Evolving Phishing Attacks Targeting Journalists and Human Rights Defenders from the Middle-East and North Africa. Retrieved October 8, 2019.
Amplia WCEAmplia Security. (n.d.). Windows Credentials Editor (WCE) F.A.Q.. Retrieved September 12, 2024.
Anatomy of an hVNC AttackKeshet, Lior. Kessem, Limor. (2017, January 25). Anatomy of an hVNC Attack. Retrieved November 28, 2023.
Anomali Evasive Maneuvers July 2015Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.
Anomali Linux Rabbit 2018Anomali Labs. (2018, December 6). Pulling Linux Rabbit/Rabbot Malware Out of a Hat. Retrieved March 4, 2019.
Anomali MUSTANG PANDA October 2019Anomali Threat Research. (2019, October 7). China-Based APT Mustang Panda Targets Minority Groups, Public and Private Sector Organizations. Retrieved April 12, 2021.
Anomali Pirate Panda April 2020Moore, S. et al. (2020, April 30). Anomali Suspects that China-Backed APT Pirate Panda May Be Seeking Access to Vietnam Government Data Center. Retrieved May 19, 2020.
Anomali Rocke March 2019Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.
Anomali Static Kitten February 2021Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.