ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Microsoft O365 Admin RolesAko-Adjei, K., Dickhaus, M., Baumgartner, P., Faigel, D., et. al.. (2019, October 8). About admin roles. Retrieved October 18, 2019.
Microsoft OAuth 2.0 Consent Phishing 2021Microsoft 365 Defender Threat Intelligence Team. (2021, June 14). Microsoft delivers comprehensive solution to battle rise in consent phishing emails. Retrieved December 13, 2021.
Microsoft OAuth Spam 2022Microsoft. (2023, September 22). Malicious OAuth applications abuse cloud email services to spread spam. Retrieved March 13, 2023.
Microsoft Office Add-insMicrosoft. (n.d.). Add or remove add-ins. Retrieved July 3, 2017.
Microsoft Open XML July 2017Microsoft. (2014, July 9). Introducing the Office (2007) Open XML File Formats. Retrieved July 20, 2018.
Microsoft Operation WilysupplyFlorio, E.. (2017, May 4). Windows Defender ATP thwarts Operation WilySupply software supply chain cyberattack. Retrieved February 14, 2019.
Microsoft Outlook FilesMicrosoft. (n.d.). Introduction to Outlook Data Files (.pst and .ost). Retrieved February 19, 2020.
Microsoft PEB 2021Microsoft. (2021, October 6). PEB structure (winternl.h). Retrieved November 19, 2021.
Microsoft PLATINUM April 2016Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.
Microsoft PLATINUM June 2017Kaplan, D, et al. (2017, June 7). PLATINUM continues to evolve, find ways to maintain invisibility. Retrieved February 19, 2018.
Microsoft POLONIUM June 2022Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.
Microsoft PSfromCsharp APR 2014Babinec, K. (2014, April 28). Executing PowerShell scripts from C#. Retrieved April 22, 2019.
Microsoft Peach Sandstorm 2023Microsoft Threat Intelligence. (2023, September 14). Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets. Retrieved September 18, 2023.
Microsoft Phosphorus Mar 2019Burt, T. (2019, March 27). New steps to protect customers from hacking. Retrieved May 27, 2020.
Microsoft PlayCrypt August 2022Microsoft Security Intelligence. (2022, August 27). Ransom:Win32/PlayCrypt.PA. Retrieved September 24, 2024.
Microsoft PoisonIvy 2017McCormack, M. (2017, September 15). Backdoor:Win32/Poisonivy.E. Retrieved December 21, 2020.
Microsoft PowerShell Command HistoryMicrosoft. (2020, May 13). About History. Retrieved September 4, 2020.
Microsoft PowerShell SilentlyContinueMicrosoft. (2023, March 2). $DebugPreference. Retrieved August 30, 2023.
Microsoft PowerShellB64Microsoft. (2023, February 8). about_PowerShell_exe: EncodedCommand. Retrieved March 17, 2023.
Microsoft Prestige ransomware October 2022MSTIC. (2022, October 14). New “Prestige” ransomware impacts organizations in Ukraine and Poland. Retrieved January 19, 2023.
Microsoft Primary Refresh TokenMicrosoft. (2022, September 9). What is a Primary Refresh Token?. Retrieved February 21, 2023.
Microsoft Process Wide Com KeysMicrosoft. (n.d.). Setting Process-Wide Security Through the Registry. Retrieved November 21, 2017.
Microsoft Profiling Mar 2017Microsoft. (2017, March 30). Profiling Overview. Retrieved June 24, 2020.
Microsoft Quick Assist 2024Microsoft. (2024, September 4). Use Quick Assist to help users. Retrieved March 14, 2025.
Microsoft RDP LogonsMicrosoft. (2017, April 9). Allow log on through Remote Desktop Services. Retrieved August 5, 2024.
Microsoft RDP RemovalMicrosoft. (2021, September 24). How to remove entries from the Remote Desktop Connection Computer box. Retrieved June 15, 2022.
Microsoft Ransomware as a ServiceMicrosoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.
Microsoft RaspberryRobin 2022Microsoft Threat Intelligence. (2022, October 27). Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity. Retrieved May 17, 2024.
Microsoft RegMicrosoft. (2012, April 17). Reg. Retrieved May 1, 2015.
Microsoft Reghide NOV 2006Russinovich, M. & Sharkey, K. (2006, January 10). Reghide. Retrieved August 9, 2018.
Microsoft Registry DriversMicrosoft. (2021, December 14). Registry Trees for Devices and Drivers. Retrieved March 28, 2023.
Microsoft Regsvr32Microsoft. (2015, August 14). How to use the Regsvr32 tool and troubleshoot Regsvr32 error messages. Retrieved June 22, 2016.
Microsoft RemoteMicrosoft. (n.d.). Enable the Remote Registry Service. Retrieved May 1, 2015.
Microsoft Remote Desktop ServicesMicrosoft. (2019, August 23). About Remote Desktop Services. Retrieved March 28, 2022.
Microsoft Royal ransomware November 2022MSTIC. (2022, November 17). DEV-0569 finds new ways to deliver Royal ransomware, various payloads. Retrieved March 30, 2023.
Microsoft Run CommandMicrosoft. (2023, March 10). Run scripts in your VM by using Run Command. Retrieved March 13, 2023.
Microsoft Run KeyMicrosoft. (n.d.). Run and RunOnce Registry Keys. Retrieved September 12, 2024.
Microsoft RunAsMicrosoft. (2016, August 31). Runas. Retrieved October 1, 2021.
Microsoft SAMMicrosoft. (2006, October 30). How to use the SysKey utility to secure the Windows Security Accounts Manager database. Retrieved August 3, 2016.
Microsoft SAML Token LifetimesMicrosoft. (2020, December 14). Configurable token lifetimes in Microsoft Identity Platform. Retrieved December 22, 2020.
Microsoft SDelete July 2016Russinovich, M. (2016, July 4). SDelete v2.0. Retrieved February 8, 2018.
Microsoft SIDMicrosoft. (n.d.). Security Identifiers. Retrieved November 30, 2017.
Microsoft SID-History AttributeMicrosoft. (n.d.). Active Directory Schema - SID-History attribute. Retrieved November 30, 2017.
Microsoft SIR Vol 19Anthe, C. et al. (2015, October 19). Microsoft Security Intelligence Report Volume 19. Retrieved December 23, 2015.
Microsoft SIR Vol 21Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.
Microsoft SPNMicrosoft. (n.d.). Service Principal Names. Retrieved March 22, 2018.
Microsoft SQL ServerMicrosoft Threat Intelligence. (2023, October 3). Defending new vectors: Threat actors attempt SQL Server to cloud lateral movement. Retrieved October 3, 2023.
Microsoft STRONTIUM Aug 2019MSRC Team. (2019, August 5). Corporate IoT – a path to intrusion. Retrieved August 16, 2019.
Microsoft STRONTIUM New Patterns Cred Harvesting Sept 2020Microsoft Threat Intelligence Center (MSTIC). (2020, September 10). STRONTIUM: Detecting new patterns in credential harvesting. Retrieved September 11, 2020.
Microsoft SecurityMicrosoft Incident Response. (2023, April 11). Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign. Retrieved February 12, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.