Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Kubernetes DaemonSet | Kubernetes. (n.d.). DaemonSet. Retrieved February 15, 2024. |
| Kubernetes Dashboard | The Kubernetes Authors. (n.d.). Kubernetes Web UI (Dashboard). Retrieved March 29, 2021. |
| Kubernetes Jobs | The Kubernetes Authors. (n.d.). Kubernetes Jobs. Retrieved March 30, 2021. |
| Kubernetes Kubelet | The Kubernetes Authors. (n.d.). Kubelet. Retrieved March 29, 2021. |
| Kubernetes RBAC | Kubernetes. (n.d.). Role Based Access Control Good Practices. Retrieved March 8, 2023. |
| Kubernetes Service Accounts | Kubernetes. (2022, February 26). Configure Service Accounts for Pods. Retrieved April 1, 2022. |
| Kubernetes Service Accounts Security | Kubernetes. (n.d.). Service Accounts. Retrieved July 14, 2023. |
| Kubernetes Workload Management | Kubernetes. (n.d.). Workload Management. Retrieved March 28, 2024. |
| LIBC | Kerrisk, M. (2016, December 12). libc(7) — Linux manual page. Retrieved June 25, 2020. |
| LLMs and Unicode - Medium | Idan Habler. (2025, September 12). Hiding in Plain Sight: Weaponizing Invisible Unicode to Attack LLMs. Retrieved April 21, 2026. |
| LOLBAS /Dfsvc.exe | LOLBAS. (n.d.). /Dfsvc.exe. Retrieved September 9, 2024. |
| LOLBAS Certutil | LOLBAS. (n.d.). Certutil.exe. Retrieved July 31, 2019. |
| LOLBAS Esentutl | LOLBAS. (n.d.). Esentutl.exe. Retrieved September 3, 2019. |
| LOLBAS Expand | LOLBAS. (n.d.). Expand.exe. Retrieved February 19, 2019. |
| LOLBAS Installutil | LOLBAS. (n.d.). Installutil.exe. Retrieved July 31, 2019. |
| LOLBAS Main Site | LOLBAS. (n.d.). Living Off The Land Binaries and Scripts (and also Libraries). Retrieved February 10, 2020. |
| LOLBAS Mavinject | LOLBAS. (n.d.). Mavinject.exe. Retrieved September 22, 2021. |
| LOLBAS Msbuild | LOLBAS. (n.d.). Msbuild.exe. Retrieved July 31, 2019. |
| LOLBAS Mshta | LOLBAS. (n.d.). Mshta.exe. Retrieved July 31, 2019. |
| LOLBAS Msiexec | LOLBAS. (n.d.). Msiexec.exe. Retrieved April 18, 2019. |
| LOLBAS Odbcconf | LOLBAS. (n.d.). Odbcconf.exe. Retrieved March 7, 2019. |
| LOLBAS Project | Oddvar Moe et al. (2022, February). Living Off The Land Binaries, Scripts and Libraries. Retrieved March 7, 2022. |
| LOLBAS Project GitHub Device Cred Dep | Elliot Killick. (n.d.). /DeviceCredentialDeployment.exe. Retrieved July 22, 2025. |
| LOLBAS Regasm | LOLBAS. (n.d.). Regasm.exe. Retrieved July 31, 2019. |
| LOLBAS Regsvcs | LOLBAS. (n.d.). Regsvcs.exe. Retrieved July 31, 2019. |
| LOLBAS Regsvr32 | LOLBAS. (n.d.). Regsvr32.exe. Retrieved July 31, 2019. |
| LOLBAS Tracker | LOLBAS. (n.d.). Tracker.exe. Retrieved July 31, 2019. |
| LOLBAS Verclsid | LOLBAS. (n.d.). Verclsid.exe. Retrieved August 10, 2020. |
| LOLBAS Wmic | LOLBAS. (n.d.). Wmic.exe. Retrieved July 31, 2019. |
| LOLESXi | Janantha Marasinghe. (n.d.). Living Off The Land ESXi. Retrieved April 14, 2025. |
| Lab52 MUSTANG PANDA PUBLOAD MAY 2023 | Dex. (n.d.). New Mustang Panda’s campaing against Australia. Retrieved August 4, 2025. |
| Lab52 WIRTE Apr 2019 | S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019. |
| Lacework AI Resource Hijacking 2024 | Detecting AI resource-hijacking with Composite Alerts. (2024, June 6). Lacework Labs. Retrieved July 1, 2024. |
| Lacework LLMJacking 2024 | Lacework Labs. (2024, June 6). Detecting AI resource-hijacking with Composite Alerts. Retrieved September 25, 2024. |
| Lacework TeamTNT May 2021 | Stroud, J. (2021, May 25). Taking TeamTNT's Docker Images Offline. Retrieved September 16, 2024. |
| Lakshmanan Visual Studio Marketplace | Lakshmanan, R. (2023, January 9). Hackers Can Abuse Visual Studio Marketplace to Target Developers with Malicious Extensions. Retrieved March 30, 2025. |
| Langer Stuxnet | Ralph Langner. (2013, November). To Kill a Centrifuge: A Technical Analysis of What Stuxnet's Creators Tried to Achieve. Retrieved December 7, 2020. |
| Lastline DarkHotel Just In Time Decryption Nov 2015 | Arunpreet Singh, Clemens Kolbitsch. (2015, November 5). Defeating Darkhotel Just-In-Time Decryption. Retrieved April 15, 2021. |
| Lastline PlugX Analysis | Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015. |
| Latrodectus APR 2024 | Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024. |
| Lau 2011 | Lau, H. (2011, August 8). Are MBR Infections Back in Fashion? (Infographic). Retrieved November 13, 2014. |
| Launch Services Apple Developer | Apple. (n.d.). Launch Services. Retrieved October 5, 2021. |
| LaunchDaemon Hijacking | Bradley Kemp. (2021, May 10). LaunchDaemon Hijacking: privilege escalation and persistence via insecure folder permissions. Retrieved July 26, 2021. |
| Launchctl Man | SS64. (n.d.). launchctl. Retrieved March 28, 2020. |
| Lazarus APT January 2022 | Saini, A. and Hossein, J. (2022, January 27). North Korea’s Lazarus APT leverages Windows Update client, GitHub in latest campaign. Retrieved January 27, 2022. |
| Lazarus RATANKBA | Lei, C., et al. (2018, January 24). Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More. Retrieved May 22, 2018. |
| Learn XPC Exploitation | Wojciech Reguła. (2020, June 29). Learn XPC exploitation. Retrieved October 12, 2021. |
| Lee 2013 | Lee, T., Hanzlik, D., Ahl, I. (2013, August 7). Breaking Down the China Chopper Web Shell - Part I. Retrieved March 27, 2015. |
| Leitch Hollowing | Leitch, J. (n.d.). Process Hollowing. Retrieved September 12, 2024. |
| Leonard TAG 2023 | Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.