Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Anomali Template Injection MAR 2018 | Intel_Acquisition_Team. (2018, March 1). Credential Harvesting and Malicious File Delivery using Microsoft Office Template Injection. Retrieved July 20, 2018. |
| AnonHBGary | Bright, P. (2011, February 15). Anonymous speaks: the inside story of the HBGary hack. Retrieved March 9, 2017. |
| Anonymous Hackers Deface Russian Govt Site | Andy. (2018, May 12). ‘Anonymous’ Hackers Deface Russian Govt. Site to Protest Web-Blocking (NSFW). Retrieved April 19, 2019. |
| Anthropic AI Orchestrated Campaign NOV 2025 | Anthropic. (2025, November). Disrupting the first reported AI-orchestrated cyber espionage campaign. Retrieved April 20, 2026. |
| Anthropic Disrupting AI Espionage NOV 2025 | Anthropic. (2025, November 13). Disrupting the first reported AI-orchestrated cyber espionage campaign. Retrieved April 20, 2026. |
| Antiquated Mac Malware | Thomas Reed. (2017, January 18). New Mac backdoor using antiquated code. Retrieved July 5, 2017. |
| Antiy CERT Ramsay April 2020 | Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021. |
| AnyRun TimeBomb | Malicious History. (2020, September 17). Time Bombs: Malware With Delayed Execution. Retrieved April 22, 2021. |
| AppInit Registry | Microsoft. (2006, October). Working with the AppInit_DLLs registry value. Retrieved July 15, 2015. |
| AppInit Secure Boot | Microsoft. (n.d.). AppInit DLLs and Secure Boot. Retrieved July 15, 2015. |
| AppSecco Kubernetes Namespace Breakout 2020 | Abhisek Datta. (2020, March 18). Kubernetes Namespace Breakout using Insecure Host Path Volume — Part 1. Retrieved January 16, 2024. |
| Apple About Mac Scripting 2016 | Apple. (2016, June 13). About Mac Scripting. Retrieved April 14, 2021. |
| Apple AppleScript | Apple. (2016, January 25). Introduction to AppleScript Language Guide. Retrieved March 28, 2020. |
| Apple Core Services | Apple. (n.d.). Core Services. Retrieved June 25, 2020. |
| Apple Culprit Access | rjben. (2012, May 30). How do you find the culprit when unauthorized access to a computer is a problem?. Retrieved August 3, 2022. |
| Apple Dev Dynamic Libraries | Apple. (2012, July 23). Overview of Dynamic Libraries. Retrieved September 7, 2023. |
| Apple Dev SecurityD | Apple. (n.d.). Security Server and Security Agent. Retrieved March 29, 2024. |
| Apple Developer Doco Archive Launchd | Apple. (2016, September 13). Daemons and Services Programming Guide - Creating Launch Daemons and Agents. Retrieved February 24, 2021. |
| Apple Disable SIP | Apple. (n.d.). Disabling and Enabling System Integrity Protection. Retrieved April 22, 2021. |
| Apple Doco Archive Dynamic Libraries | Apple Inc.. (2012, July 23). Overview of Dynamic Libraries. Retrieved March 24, 2021. |
| Apple Kernel Extension Deprecation | Apple. (n.d.). Deprecated Kernel Extensions and System Extension Alternatives. Retrieved November 4, 2020. |
| Apple PAM | Apple. (2011, May 11). PAM - Pluggable Authentication Modules. Retrieved June 25, 2020. |
| Apple Remote Desktop Admin Guide 3.3 | Apple. (n.d.). Apple Remote Desktop Administrator Guide Version 3.3. Retrieved October 5, 2021. |
| Apple Support Hide a User Account | Apple. (2020, November 30). Hide a user account in macOS. Retrieved December 10, 2021. |
| Apple Unified Log Analysis Remote Login and Screen Sharing | Sarah Edwards. (2020, April 30). Analysis of Apple Unified Logs: Quarantine Edition [Entry 6] – Working From Home? Remote Logins. Retrieved August 19, 2021. |
| Apple ZShell | Apple. (2020, January 28). Use zsh as the default shell on your Mac. Retrieved June 12, 2020. |
| AppleDocs AuthorizationExecuteWithPrivileges | Apple. (n.d.). Apple Developer Documentation - AuthorizationExecuteWithPrivileges. Retrieved August 8, 2019. |
| AppleDocs Launch Agent Daemons | Apple. (n.d.). Creating Launch Daemons and Agents. Retrieved July 10, 2017. |
| Application Bundle Manipulation Brandon Dalton | Brandon Dalton. (2022, August 9). A bundle of nerves: Tweaking macOS security controls to thwart application bundle manipulation. Retrieved September 27, 2022. |
| April 2021 TrendMicro XCSSET | Steven Du, Dechao Zhao, Luis Magisa, Ariel Neimond Lazaro. (2021, April 16). XCSSET Quickly Adapts to macOS 11 and M1-based Macs. Retrieved February 18, 2025. |
| Apriorit | Apriorit. (2024, June 4). Anti Debugging Protection Techniques with Examples. Retrieved March 4, 2025. |
| Aqua Build Images on Hosts | Assaf Morag. (2020, July 15). Threat Alert: Attackers Building Malicious Images on Your Hosts. Retrieved March 29, 2021. |
| Aqua Kinsing April 2020 | Singer, G. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved April 1, 2021. |
| Aqua Security Blog Trivy Compromise APR 2026 | Aqua Team. (2026, April 1). Update: Ongoing Investigation and Continued Remediation. Retrieved July 1, 2026. |
| Aqua Security Cloud Native Threat Report June 2021 | Team Nautilus. (2021, June). Attacks in the Wild on the Container Supply Chain and Infrastructure. Retrieved August 26, 2021. |
| Aqua Security Trivy Compromise MAR 2026 | Aqua Security . (2026, March 21). Trivy ecosystem supply chain temporarily compromised. Retrieved July 1, 2026. |
| Aqua TeamTNT August 2020 | Kol, Roi. Morag, A. (2020, August 25). Deep Analysis of TeamTNT Techniques Using Container Images to Attack. Retrieved September 22, 2021. |
| AquaSec TeamTNT 2023 | Ofek Itach and Assaf Morag. (2023, July 13). TeamTNT Reemerged with New Aggressive Cloud Campaign. Retrieved February 15, 2024. |
| Aquasec Kinsing 2020 | Gal Singer. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved May 22, 2025. |
| Aquasec Kubernetes Attack 2023 | Michael Katchinskiy, Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved July 14, 2023. |
| Aquasec Kubernetes Backdoor 2023 | Michael Katchinskiy and Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved March 24, 2025. |
| Aquasec Muhstik Malware 2024 | Nitzan Yaakov. (2024, June 4). Muhstik Malware Targets Message Queuing Services Applications. Retrieved September 24, 2024. |
| Aquino RARSTONE | Aquino, M. (2013, June 13). RARSTONE Found In Targeted Attacks. Retrieved December 17, 2015. |
| Arbor AnnualDoSreport Jan 2018 | Philippe Alcoy, Steinthor Bjarnason, Paul Bowen, C.F. Chui, Kirill Kasavchnko, and Gary Sockrider of Netscout Arbor. (2018, January). Insight into the Global Threat Landscape - Netscout Arbor's 13th Annual Worldwide Infrastructure Security… |
| Arbor Musical Chairs Feb 2018 | Sabo, S. (2018, February 15). Musical Chairs Playing Tetris. Retrieved February 19, 2018. |
| Arbor SSLDoS April 2012 | ASERT Team, Netscout Arbor. (2012, April 24). DDoS Attacks on SSL: Something Old, Something New. Retrieved April 22, 2019. |
| Arch Linux Package Systemd Compromise BleepingComputer 10JUL2018 | Catalin Cimpanu. (2018, July 10). Malware Found in Arch Linux AUR Package Repository. Retrieved April 23, 2019. |
| Arctic Wolf | Julian Tuin, Stefan Hostetler, Jon Grimm, Aaron Diaz, and Trevor Daher. (2024, November 22). Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices. Retrieved January 8, 2025. |
| Arctic Wolf Akira 2023 | Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024. |
| Arghire LazyScripter | Ionut Arghire. (2021, February 24). New ‘LazyScripter’ Hacking Group Targets Airlines. Retrieved January 10, 2024. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.