Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| McAfee Malicious Doc Targets Pyeongchang Olympics | Saavedra-Morales, J., Sherstobitoff, R. (2018, January 6). Malicious Document Targets Pyeongchang Olympics. Retrieved April 10, 2018. |
| McAfee Maze March 2020 | Mundo, A. (2020, March 26). Ransomware Maze. Retrieved May 18, 2020. |
| McAfee Netwire Mar 2015 | McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018. |
| McAfee Night Dragon | McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018. |
| McAfee Oceansalt Oct 2018 | Sherstobitoff, R., Malhotra, A. (2018, October 18). ‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group. Retrieved November 30, 2018. |
| McAfee REvil October 2019 | Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020. |
| McAfee RedLine Stealer April 2024 | Mohansundaram M, Neil Tyagi. (2024, April 17). Redline Stealer: A Novel Approach. Retrieved September 17, 2025. |
| McAfee Sandworm November 2013 | Li, H. (2013, November 5). McAfee Labs Detects Zero-Day Exploit Targeting Microsoft Office. Retrieved June 18, 2020. |
| McAfee Shamoon December 2018 | Mundo, A., Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 14). Shamoon Returns to Wipe Systems in Middle East, Europe . Retrieved May 29, 2020. |
| McAfee Shamoon December19 2018 | Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 19). Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems. Retrieved May 29, 2020. |
| McAfee Sharpshooter December 2018 | Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020. |
| McAfee Sodinokibi October 2019 | McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020. |
| McAfee Virtual Jan 2017 | Roccia, T. (2017, January 19). Stopping Malware With a Fake Virtual Machine. Retrieved April 17, 2019. |
| McAfee-GhostSecret-fixurl | Ryan Sherstobitoff. (2018, April 24). Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide. Retrieved August 15, 2024. |
| McMillan Pwn March 2012 | Robert McMillan. (2012, March 3). The Pwn Plug is a little white box that can hack your network. Retrieved March 30, 2018. |
| Mcafee Clop Aug 2019 | Mundo, A. (2019, August 1). Clop Ransomware. Retrieved May 10, 2021. |
| Medium | Michael Koczwara. (2021, March 14). Windows privilege escalation via PowerShell History. Retrieved June 13, 2025. |
| Medium 777-Botnet | Gi7w0rm. (2023, October 19). The curious case of the 7777-Botnet. Retrieved June 5, 2025. |
| Medium Ali Salem Bumblebee April 2022 | Salem, A. (2022, April 27). The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connection. Retrieved September 2, 2022. |
| Medium Anchor DNS July 2020 | Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020. |
| Medium Babuk February 2021 | Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021. |
| Medium Certified Pre Owned | Schroeder, W. (2021, June 17). Certified Pre-Owned. Retrieved August 2, 2022. |
| Medium DnsTunneling | Galobardes, R. (2018, October 30). Learn how easy is to bypass firewalls using DNS tunneling (and also how to block it). Retrieved March 15, 2020. |
| Medium Eli Salem GuLoader April 2021 | Salem, E. (2021, April 19). Dancing With Shellcodes: Cracking the latest version of Guloader. Retrieved July 7, 2021. |
| Medium KONNI Jan 2020 | Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020. |
| Medium Metamorfo Apr 2020 | Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020. |
| Medium Ptrace JUL 2018 | Jain, S. (2018, July 25). Code injection in running process using ptrace. Retrieved February 21, 2020. |
| Medium S2W WhisperGate January 2022 | S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022. |
| Medium SSL Cert | Jain, M. (2019, September 16). Export & Download — SSL Certificate from Server (Site URL). Retrieved October 20, 2020. |
| MehtaFastFluxPt1 | Mehta, L. (2014, December 17). Fast Flux Networks Working and Detection, Part 1. Retrieved March 6, 2017. |
| MehtaFastFluxPt2 | Mehta, L. (2014, December 23). Fast Flux Networks Working and Detection, Part 2. Retrieved March 6, 2017. |
| MelikovBlackBerry LightSpy 2024 | Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025. |
| Metabase Q Mispadu Trojan 2023 | Garcia, F., Regalado, D. (2023, March 7). Inside Mispadu massive infection campaign in LATAM. Retrieved March 15, 2024. |
| Metasploit SSH Module | undefined. (n.d.). Retrieved April 12, 2019. |
| Metcalf 2015 | Metcalf, S. (2015, January 19). Attackers Can Now Use Mimikatz to Implant Skeleton Key on Domain Controllers & BackDoor Your Active Directory Forest. Retrieved February 3, 2015. |
| Methods of Mac Malware Persistence | Patrick Wardle. (2014, September). Methods of Malware Persistence on Mac OS X. Retrieved July 5, 2017. |
| Meyer PyPI Supply Chain Attack Uncovered | Darren Meyer. (2025, May 28). PyPI Supply Chain Attack Uncovered: Colorama and Colorizr Name Confusion. Retrieved September 24, 2025. |
| Meyers Numbered Panda | Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016. |
| MicroFocus 9002 Aug 2016 | Petrovsky, O. (2016, August 30). “9002 RAT” -- a second building on the left. Retrieved February 20, 2018. |
| Microsoft - Add-MailboxPermission | Microsoft. (n.d.). Add-Mailbox Permission. Retrieved September 13, 2019. |
| Microsoft - Azure AD App Registration - May 2019 | Microsoft. (2019, May 8). Quickstart: Register an application with the Microsoft identity platform. Retrieved September 12, 2019. |
| Microsoft - Azure AD Federation | Microsoft. (2018, November 28). What is federation with Azure AD?. Retrieved December 30, 2020. |
| Microsoft - Azure AD Identity Tokens - Aug 2019 | Microsoft. (2019, August 29). Microsoft identity platform access tokens. Retrieved September 12, 2019. |
| Microsoft - Azure PowerShell | Microsoft. (2014, December 12). Azure/azure-powershell. Retrieved March 24, 2023. |
| Microsoft - Cached Creds | Microsoft. (2016, August 21). Cached and Stored Credentials Technical Overview. Retrieved February 21, 2020. |
| Microsoft - Customer Guidance on Recent Nation-State Cyber Attacks | MSRC. (2020, December 13). Customer Guidance on Recent Nation-State Cyber Attacks. Retrieved December 30, 2020. |
| Microsoft - Device Registration | Microsoft 365 Defender Threat Intelligence Team. (2022, January 26). Evolved phishing: Device registration trick adds to phishers’ toolbox for victims without MFA. Retrieved March 4, 2022. |
| Microsoft - OAuth Code Authorization flow - June 2019 | Microsoft. (n.d.). Microsoft identity platform and OAuth 2.0 authorization code flow. Retrieved September 12, 2019. |
| Microsoft - manifests/assembly | Microsoft. (2021, January 7). Manifests. Retrieved January 30, 2025. |
| Microsoft 365 Defender Solorigate | Microsoft 365 Defender Team. (2020, December 28). Using Microsoft 365 Defender to protect against Solorigate. Retrieved January 7, 2021. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.