Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Microsoft CreateProcess | Microsoft. (n.d.). CreateProcess function. Retrieved September 12, 2024. |
| Microsoft CredEnumerate | Microsoft. (2018, December 5). CredEnumarateA function (wincred.h). Retrieved November 24, 2020. |
| Microsoft Credential Locker | Microsoft. (2013, October 23). Credential Locker Overview. Retrieved November 24, 2020. |
| Microsoft Credential Manager store | Microsoft. (2016, August 31). Cached and Stored Credentials Technical Overview. Retrieved November 24, 2020. |
| Microsoft CryptUnprotectData April 2018 | Microsoft. (2018, April 12). CryptUnprotectData function. Retrieved June 18, 2019. |
| Microsoft Cryptojacking 2023 | Microsoft Threat Intelligence. (2023, July 25). Cryptojacking: Understanding and defending against cloud compute resource abuse. Retrieved September 5, 2023. |
| Microsoft CurrentControlSet Services | Microsoft. (2017, April 20). HKLM\SYSTEM\CurrentControlSet\Services Registry Tree. Retrieved March 16, 2020. |
| Microsoft DACL May 2018 | Microsoft. (2018, May 30). DACLs and ACEs. Retrieved August 19, 2018. |
| Microsoft DART Case Report 001 | Berk Veral. (2020, March 9). Real-life cybercrime stories from DART, the Microsoft Detection and Response Team. Retrieved May 27, 2022. |
| Microsoft DDE Advisory Nov 2017 | Microsoft. (2017, November 8). Microsoft Security Advisory 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields. Retrieved November 21, 2017. |
| Microsoft DEV-0537 | Microsoft. (2022, March 22). DEV-0537 criminal actor targeting organizations for data exfiltration and destruction. Retrieved March 23, 2022. |
| Microsoft DLL | Microsoft. (2023, April 28). What is a DLL. Retrieved September 7, 2023. |
| Microsoft DRSR Dec 2017 | Microsoft. (2017, December 1). MS-DRSR Directory Replication Service (DRS) Remote Protocol. Retrieved December 4, 2017. |
| Microsoft DSE June 2017 | Microsoft. (2017, June 1). Digital Signatures for Kernel Modules on Windows. Retrieved April 22, 2021. |
| Microsoft DTC | Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016. |
| Microsoft DUBNIUM July 2016 | Microsoft. (2016, July 14). Reverse engineering DUBNIUM – Stage 2 payload analysis . Retrieved March 31, 2021. |
| Microsoft DUBNIUM June 2016 | Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021. |
| Microsoft Deep Dive Solorigate January 2021 | MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021. |
| Microsoft Deploying AD Federation | Microsoft. (n.d.). Deploying Active Directory Federation Services in Azure. Retrieved March 13, 2020. |
| Microsoft Detecting Kerberoasting Feb 2018 | Bani, M. (2018, February 23). Detecting Kerberoasting activity using Azure Security Center. Retrieved March 23, 2018. |
| Microsoft Dev Blog IFEO Mar 2010 | Shanbhag, M. (2010, March 24). Image File Execution Options (IFEO). Retrieved December 18, 2017. |
| Microsoft DiamondSleet 2023 | Microsoft Threat Intelligence. (2023, November 22). Diamond Sleet supply chain compromise distributes a modified CyberLink installer. Retrieved March 28, 2025. |
| Microsoft Digital Defense FY20 Sept 2020 | Microsoft . (2020, September 29). Microsoft Digital Defense Report FY20. Retrieved April 21, 2021. |
| Microsoft Dofoil 2018 | Windows Defender Research. (2018, March 7). Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign. Retrieved March 20, 2018. |
| Microsoft Driverquery | Microsoft. (n.d.). driverquery. Retrieved March 28, 2023. |
| Microsoft East Asia Threats September 2023 | Microsoft Threat Intelligence. (2023, September). Digital threats from East Asia increase in breadth and effectiveness. Retrieved February 5, 2024. |
| Microsoft Entra ID App Passwords | Microsoft. (2023, October 23). Enforce Microsoft Entra multifactor authentication with legacy applications using app passwords. Retrieved May 28, 2024. |
| Microsoft Entra ID Service Principals | Microsoft. (2023, December 15). Application and service principal objects in Microsoft Entra ID. Retrieved February 28, 2024. |
| Microsoft EnumDeviceDrivers | Microsoft. (2021, October 12). EnumDeviceDrivers function (psapi.h). Retrieved March 28, 2023. |
| Microsoft Environment Property | Microsoft. (2011, October 24). Environment Property. Retrieved July 27, 2016. |
| Microsoft Esentutl | Microsoft. (2016, August 30). Esentutl. Retrieved September 3, 2019. |
| Microsoft Exchange Address Lists | Microsoft. (2020, February 7). Address lists in Exchange Server. Retrieved March 26, 2020. |
| Microsoft Expand Utility | Microsoft. (2017, October 15). Expand. Retrieved February 19, 2019. |
| Microsoft FTP | Microsoft. (2021, July 21). ftp. Retrieved February 25, 2022. |
| Microsoft File Folder Exclusions | Microsoft. (2024, February 27). Contextual file and folder exclusions. Retrieved March 29, 2024. |
| Microsoft File Handlers | Microsoft. (n.d.). Specifying File Handlers for File Name Extensions. Retrieved September 12, 2024. |
| Microsoft File Streams | Microsoft. (n.d.). File Streams. Retrieved September 12, 2024. |
| Microsoft Fileless | Microsoft. (2023, February 6). Fileless threats. Retrieved March 23, 2023. |
| Microsoft FinFisher March 2018 | Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018. |
| Microsoft Forfiles Aug 2016 | Microsoft. (2016, August 31). Forfiles. Retrieved January 22, 2018. |
| Microsoft GALLIUM December 2019 | MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021. |
| Microsoft GFlags Mar 2017 | Microsoft. (2017, May 23). GFlags Overview. Retrieved December 18, 2017. |
| Microsoft GPP 2016 | Microsoft. (2016, August 31). Group Policy Preferences. Retrieved March 9, 2020. |
| Microsoft GPP Key | Microsoft. (n.d.). 2.2.1.1.4 Password Encryption. Retrieved April 11, 2018. |
| Microsoft GetNCCChanges | Microsoft. (n.d.). IDL_DRSGetNCChanges (Opnum 3). Retrieved December 4, 2017. |
| Microsoft GetWindowLong function | Microsoft. (n.d.). GetWindowLong function. Retrieved December 16, 2017. |
| Microsoft Gsecdump | Vincent Tiu. (2017, September 15). HackTool:Win32/Gsecdump. Retrieved January 10, 2024. |
| Microsoft HAFNIUM March 2020 | MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021. |
| Microsoft HTML Help ActiveX | Microsoft. (n.d.). HTML Help ActiveX Control Overview. Retrieved October 3, 2018. |
| Microsoft HTML Help Executable Program | Microsoft. (n.d.). About the HTML Help Executable Program. Retrieved October 3, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.