ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Leonardo Turla Penquin May 2020Leonardo. (2020, May 29). MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64”. Retrieved March 11, 2021.
Let's Encrypt FAQLet's Encrypt. (2020, April 23). Let's Encrypt FAQ. Retrieved October 15, 2020.
LevelBlue Blind Eagle Proton66 JUN 2025Melnyk, S. (2025, June 27). Tracing Blind Eagle to Proton66. Retrieved April 16, 2026.
Linux FTPN/A. (n.d.). ftp(1) - Linux man page. Retrieved February 25, 2022.
Linux IPCN/A. (2021, April 1). Inter Process Communication (IPC). Retrieved March 11, 2022.
Linux Kerberos TicketsTrevor Haskell. (2020, April 1). Kerberos Tickets on Linux Red Teams. Retrieved October 4, 2021.
Linux Kernel APILinux Kernel Organization, Inc. (n.d.). The Linux Kernel API. Retrieved June 25, 2020.
Linux Kernel Module Programming GuidePomerantz, O., Salzman, P. (2003, April 4). Modules vs Programs. Retrieved November 17, 2024.
Linux Kernel ProgrammingPomerantz, O., Salzman, P.. (2003, April 4). The Linux Kernel Module Programming Guide. Retrieved April 6, 2018.
Linux LogsMarcel. (2018, April 19). 12 Critical Linux Log Files You Must be Monitoring. Retrieved March 29, 2020.
Linux Password and Shadow File FormatsThe Linux Documentation Project. (n.d.). Linux Password and Shadow File Formats. Retrieved February 19, 2020.
Linux Shared LibrariesWheeler, D. (2003, April 11). Shared Libraries. Retrieved September 7, 2023.
Linux Signal ManLinux man-pages. (2023, April 3). signal(7). Retrieved August 30, 2023.
Linux UsermodMan7. (n.d.). Usermod. Retrieved August 5, 2024.
Linux atIEEE/The Open Group. (2017). at(1p) — Linux manual page. Retrieved February 25, 2022.
Linux man-pages: systemd January 2014Linux man-pages. (2014, January). systemd(1) - Linux manual page. Retrieved April 23, 2019.
Linux manual bash invocationArchWiki. (2021, January 19). Bash. Retrieved February 25, 2021.
Linux/Cdorked.A We Live Security AnalysisPierre-Marc Bureau. (2013, April 26). Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole. Retrieved September 10, 2017.
List BlobsMicrosoft - List Blobs. (n.d.). Retrieved October 4, 2021.
ListObjectsV2Amazon - ListObjectsV2. Retrieved October 4, 2021.
Lockboxx ARD 2019Dan Borges. (2019, July 21). MacOS Red Teaming 206: ARD (Apple Remote Desktop Protocol). Retrieved September 10, 2021.
LogRhythm Do You Trust Oct 2014Foss, G. (2014, October 3). Do You Trust Your Computer?. Retrieved December 17, 2018.
LogRhythm WannaCryNoerenberg, E., Costis, A., and Quist, N. (2017, May 16). A Technical Analysis of WannaCry Ransomware. Retrieved December 8, 2024.
Login Items AEApple. (n.d.). Login Items AE. Retrieved October 4, 2021.
Login Scripts Apple DevApple. (2016, September 13). Customizing Login and Logout. Retrieved April 1, 2022.
LoginWindowScripts Apple DevApple. (n.d.). LoginWindowScripts. Retrieved April 1, 2022.
LogonUserW functionMicrosoft. (2023, March 10). LogonUserW function (winbase.h). Retrieved January 8, 2024.
Logpoint Pikabot 2024Swachchhanda Shrawan Poudel. (2024, February). Pikabot: 
 A Sophisticated and Modular Backdoor Trojan with Advanced Evasion Techniques. Retrieved July 12, 2024.
Lookout Dark Caracal Jan 2018Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.
Lotus Blossom Dec 2015Falcone, R. and Miller-Osborn, J.. (2015, December 18). Attack on French Diplomat Linked to Operation Lotus Blossom. Retrieved February 15, 2016.
Lotus Blossom Jun 2015Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.
Low GroupIB xattrs nov 2024Sharmine Low. (2024, November 13). Stealthy Attributes of Lazarus APT Group: Evading Detection with Extended Attributes. Retrieved March 27, 2025.
Lua Proofpoint SunseedRaggi, Michael. Cass, Zydeca. The Proofpoint Threat Research Team.. (2022, March 1). Asylum Ambuscade: State Actor Uses Lua-based Sunseed Malware to Target European Governments and Refugee Movement. Retrieved August 5, 2024.
Lua main pageLua. (2024, June 25). Getting started. Retrieved August 5, 2024.
Lua stateLua. (n.d.). lua_State. Retrieved August 5, 2024.
Lumen J-Magic JAN 2025Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.
Lumen KVBotnet 2023Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.
Lumen Versa 2024Black Lotus Labs. (2024, August 27). Taking The Crossroads: The Versa Director Zero-Day Exploitaiton. Retrieved August 27, 2024.
Lumen_SystemBC_Sept2025Black Lotus Labs . (2025, September 18). SystemBC: Bringing the noise. Retrieved December 15, 2025.
Lunghi Iron Tiger LinuxDaniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.
MACOS CocoaApple. (2015, September 16). Cocoa Application Layer. Retrieved June 25, 2020.
MAGNET GOBLINCheck Point Research. (2024, March 8). MAGNET GOBLIN TARGETS PUBLICLY FACING SERVERS USING 1-DAY VULNERABILITIES. Retrieved March 27, 2024.
MANDVI Malicious npm and PyPI Packages DisguisedMANDVI. (2025, April 22). Malicious npm and PyPI Packages Disguised as Dev Tools to Steal Credentials. Retrieved September 24, 2025.
MAR10135536-BUS-CERT. (2017, December 13). Malware Analysis Report (MAR) - 10135536-B. Retrieved August 15, 2024.
MAR10135536-FUS-CERT. (2018, February 5). Malware Analysis Report (MAR) - 10135536-F. Retrieved August 15, 2024.
MDSecMDSec. (n.d.). Autodial(DLL)ing Your Way. Retrieved September 25, 2025.
MDSec Brute Ratel August 2022Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.
MDSec System CallsMDSec Research. (2020, December). Bypassing User-Mode Hooks and Direct Invocation of System Calls for Red Teams. Retrieved September 29, 2021.
MDSec macOS JXA and VSCodeDominic Chell. (2021, January 1). macOS Post-Exploitation Shenanigans with VSCode Extensions. Retrieved April 20, 2021.
MFA Fatigue Attacks - PortSwiggerJessica Haworth. (2022, February 16). MFA fatigue attacks: Users tricked into allowing device access due to overload of push notifications. Retrieved March 31, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.