ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Microsoft CreateProcessMicrosoft. (n.d.). CreateProcess function. Retrieved September 12, 2024.
Microsoft CredEnumerateMicrosoft. (2018, December 5). CredEnumarateA function (wincred.h). Retrieved November 24, 2020.
Microsoft Credential LockerMicrosoft. (2013, October 23). Credential Locker Overview. Retrieved November 24, 2020.
Microsoft Credential Manager storeMicrosoft. (2016, August 31). Cached and Stored Credentials Technical Overview. Retrieved November 24, 2020.
Microsoft CryptUnprotectData April 2018Microsoft. (2018, April 12). CryptUnprotectData function. Retrieved June 18, 2019.
Microsoft Cryptojacking 2023Microsoft Threat Intelligence. (2023, July 25). Cryptojacking: Understanding and defending against cloud compute resource abuse. Retrieved September 5, 2023.
Microsoft CurrentControlSet ServicesMicrosoft. (2017, April 20). HKLM\SYSTEM\CurrentControlSet\Services Registry Tree. Retrieved March 16, 2020.
Microsoft DACL May 2018Microsoft. (2018, May 30). DACLs and ACEs. Retrieved August 19, 2018.
Microsoft DART Case Report 001Berk Veral. (2020, March 9). Real-life cybercrime stories from DART, the Microsoft Detection and Response Team. Retrieved May 27, 2022.
Microsoft DDE Advisory Nov 2017Microsoft. (2017, November 8). Microsoft Security Advisory 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields. Retrieved November 21, 2017.
Microsoft DEV-0537Microsoft. (2022, March 22). DEV-0537 criminal actor targeting organizations for data exfiltration and destruction. Retrieved March 23, 2022.
Microsoft DLLMicrosoft. (2023, April 28). What is a DLL. Retrieved September 7, 2023.
Microsoft DRSR Dec 2017Microsoft. (2017, December 1). MS-DRSR Directory Replication Service (DRS) Remote Protocol. Retrieved December 4, 2017.
Microsoft DSE June 2017Microsoft. (2017, June 1). Digital Signatures for Kernel Modules on Windows. Retrieved April 22, 2021.
Microsoft DTCMicrosoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016.
Microsoft DUBNIUM July 2016Microsoft. (2016, July 14). Reverse engineering DUBNIUM – Stage 2 payload analysis . Retrieved March 31, 2021.
Microsoft DUBNIUM June 2016Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021.
Microsoft Deep Dive Solorigate January 2021MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.
Microsoft Deploying AD FederationMicrosoft. (n.d.). Deploying Active Directory Federation Services in Azure. Retrieved March 13, 2020.
Microsoft Detecting Kerberoasting Feb 2018Bani, M. (2018, February 23). Detecting Kerberoasting activity using Azure Security Center. Retrieved March 23, 2018.
Microsoft Dev Blog IFEO Mar 2010Shanbhag, M. (2010, March 24). Image File Execution Options (IFEO). Retrieved December 18, 2017.
Microsoft DiamondSleet 2023Microsoft Threat Intelligence. (2023, November 22). Diamond Sleet supply chain compromise distributes a modified CyberLink installer. Retrieved March 28, 2025.
Microsoft Digital Defense FY20 Sept 2020Microsoft . (2020, September 29). Microsoft Digital Defense Report FY20. Retrieved April 21, 2021.
Microsoft Dofoil 2018Windows Defender Research. (2018, March 7). Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign. Retrieved March 20, 2018.
Microsoft DriverqueryMicrosoft. (n.d.). driverquery. Retrieved March 28, 2023.
Microsoft East Asia Threats September 2023Microsoft Threat Intelligence. (2023, September). Digital threats from East Asia increase in breadth and effectiveness. Retrieved February 5, 2024.
Microsoft Entra ID App PasswordsMicrosoft. (2023, October 23). Enforce Microsoft Entra multifactor authentication with legacy applications using app passwords. Retrieved May 28, 2024.
Microsoft Entra ID Service PrincipalsMicrosoft. (2023, December 15). Application and service principal objects in Microsoft Entra ID. Retrieved February 28, 2024.
Microsoft EnumDeviceDriversMicrosoft. (2021, October 12). EnumDeviceDrivers function (psapi.h). Retrieved March 28, 2023.
Microsoft Environment PropertyMicrosoft. (2011, October 24). Environment Property. Retrieved July 27, 2016.
Microsoft EsentutlMicrosoft. (2016, August 30). Esentutl. Retrieved September 3, 2019.
Microsoft Exchange Address ListsMicrosoft. (2020, February 7). Address lists in Exchange Server. Retrieved March 26, 2020.
Microsoft Expand UtilityMicrosoft. (2017, October 15). Expand. Retrieved February 19, 2019.
Microsoft FTPMicrosoft. (2021, July 21). ftp. Retrieved February 25, 2022.
Microsoft File Folder ExclusionsMicrosoft. (2024, February 27). Contextual file and folder exclusions. Retrieved March 29, 2024.
Microsoft File HandlersMicrosoft. (n.d.). Specifying File Handlers for File Name Extensions. Retrieved September 12, 2024.
Microsoft File StreamsMicrosoft. (n.d.). File Streams. Retrieved September 12, 2024.
Microsoft FilelessMicrosoft. (2023, February 6). Fileless threats. Retrieved March 23, 2023.
Microsoft FinFisher March 2018Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018.
Microsoft Forfiles Aug 2016Microsoft. (2016, August 31). Forfiles. Retrieved January 22, 2018.
Microsoft GALLIUM December 2019MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.
Microsoft GFlags Mar 2017Microsoft. (2017, May 23). GFlags Overview. Retrieved December 18, 2017.
Microsoft GPP 2016Microsoft. (2016, August 31). Group Policy Preferences. Retrieved March 9, 2020.
Microsoft GPP KeyMicrosoft. (n.d.). 2.2.1.1.4 Password Encryption. Retrieved April 11, 2018.
Microsoft GetNCCChangesMicrosoft. (n.d.). IDL_DRSGetNCChanges (Opnum 3). Retrieved December 4, 2017.
Microsoft GetWindowLong functionMicrosoft. (n.d.). GetWindowLong function. Retrieved December 16, 2017.
Microsoft GsecdumpVincent Tiu. (2017, September 15). HackTool:Win32/Gsecdump. Retrieved January 10, 2024.
Microsoft HAFNIUM March 2020MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.
Microsoft HTML Help ActiveXMicrosoft. (n.d.). HTML Help ActiveX Control Overview. Retrieved October 3, 2018.
Microsoft HTML Help Executable ProgramMicrosoft. (n.d.). About the HTML Help Executable Program. Retrieved October 3, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.