ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Microsoft Security SubsystemMicrosoft. (n.d.). Security Subsystem Architecture. Retrieved November 27, 2017.
Microsoft Service Control ManagerMicrosoft. (2018, May 31). Service Control Manager. Retrieved March 28, 2020.
Microsoft Set-InboxRuleMicrosoft. (n.d.). Set-InboxRule. Retrieved June 7, 2021.
Microsoft SetSPNMicrosoft. (2010, April 13). Service Principal Names (SPNs) SetSPN Syntax (Setspn.exe). Retrieved March 22, 2018.
Microsoft SetWindowLong functionMicrosoft. (n.d.). SetWindowLong function. Retrieved December 16, 2017.
Microsoft Shai-Hulud December 2025Microsoft Defender Security Team. (n.d.). Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack. Retrieved April 9, 2026.
Microsoft SharePoint Exploit JUL 2025Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.
Microsoft Shutdown Oct 2017Microsoft. (2017, October 15). Shutdown. Retrieved October 4, 2019.
Microsoft Silent Process Exit NOV 2017Marshall, D. & Griffin, S. (2017, November 28). Monitoring Silent Process Exit. Retrieved June 27, 2018.
Microsoft Silk Typhoon MAR 2025Microsoft Threat Intelligence . (2025, March 5). Silk Typhoon targeting IT supply chain. Retrieved March 20, 2025.
Microsoft Sliver 2022Microsoft Security Experts. (2022, August 24). Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks. Retrieved March 24, 2025.
Microsoft Smart App ControlMicrosoft. (n.d.). Smart App Control Frequently Asked Questions. Retrieved April 4, 2025.
Microsoft SolarWinds Customer GuidanceMSRC. (2020, December 13). Customer Guidance on Recent Nation-State Cyber Attacks. Retrieved December 17, 2020.
Microsoft SolarWinds StepsLambert, J. (2020, December 13). Important steps for customers to protect themselves from recent nation-state cyberattacks. Retrieved December 17, 2020.
Microsoft Star Blizzard August 2022Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.
Microsoft Storm-0501 Embargo Ransomware August 2025Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.
Microsoft Storm-0940Microsoft Threat Intelligence. (2024, October 31). Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network. Retrieved June 4, 2025.
Microsoft Storm-1811 2024Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.
Microsoft Storm-501 Sabbath Ransomware Embargo September 2024Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.
Microsoft Sub Takeover 2020Microsoft. (2020, September 29). Prevent dangling DNS entries and avoid subdomain takeover. Retrieved October 12, 2020.
Microsoft Subscription Hijacking 2022Dor Edry. (2022, August 24). Hunt for compromised Azure subscriptions using Microsoft Defender for Cloud Apps. Retrieved September 5, 2023.
Microsoft Support O365 Add Another Admin, October 2019Microsoft. (n.d.). Add Another Admin. Retrieved October 18, 2019.
Microsoft System Services FundamentalsMicrosoft. (2018, February 17). Windows System Services Fundamentals. Retrieved March 28, 2022.
Microsoft TESTSIGNING Feb 2021Microsoft. (2021, February 15). Enable Loading of Test Signed Drivers. Retrieved April 22, 2021.
Microsoft Targeting Elections September 2020Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.
Microsoft TasklistMicrosoft. (n.d.). Tasklist. Retrieved December 23, 2015.
Microsoft Threat Actor Naming July 2023Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Microsoft Tim McMichael Exchange Mail Forwarding 2McMichael, T.. (2015, June 8). Exchange and Office 365 Mail Forwarding. Retrieved October 8, 2019.
Microsoft TimeProviderMicrosoft. (n.d.). Time Provider. Retrieved March 26, 2018.
Microsoft Totbrick Oct 2017Pornasdoro, A. (2017, October 12). Trojan:Win32/Totbrick. Retrieved September 14, 2018.
Microsoft TransportAgent Jun 2016Microsoft. (2016, June 1). Transport agents. Retrieved June 24, 2019.
Microsoft TrojanSpy:Win32/Ursnif.gen!I Sept 2017Microsoft. (2017, September 15). TrojanSpy:Win32/Ursnif.gen!I. Retrieved December 18, 2017.
Microsoft TrustsMicrosoft. (2009, October 7). Trust Technologies. Retrieved February 14, 2019.
Microsoft TxFMicrosoft. (n.d.). Transactional NTFS (TxF). Retrieved December 20, 2017.
Microsoft UAC Nov 2018Montemayor, D. et al.. (2018, November 15). How User Account Control works. Retrieved June 3, 2019.
Microsoft Unidentified Dec 2018Microsoft Defender Research Team. (2018, December 3). Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers. Retrieved April 15, 2019.
Microsoft Unsigned Driver Apr 2017Microsoft. (2017, April 20). Installing an Unsigned Driver during Development and Test. Retrieved April 22, 2021.
Microsoft VBAMicrosoft. (2019, June 11). Office VBA Reference. Retrieved June 23, 2020.
Microsoft VBScriptMicrosoft. (2011, April 19). What Is VBScript?. Retrieved March 28, 2020.
Microsoft Virutal Machine APIMicrosoft. (2019, March 1). Virtual Machines - Get. Retrieved October 8, 2019.
Microsoft Volt Typhoon May 2023Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.
Microsoft W32Time Feb 2018Microsoft. (2018, February 1). Windows Time Service (W32Time). Retrieved March 26, 2018.
Microsoft Well Known SIDs Jun 2017Microsoft. (2017, June 23). Well-known security identifiers in Windows operating systems. Retrieved November 30, 2017.
Microsoft Where to use TxFMicrosoft. (n.d.). When to Use Transactional NTFS. Retrieved December 20, 2017.
Microsoft WhisperGate January 2022MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.
Microsoft Win Defender Truvasys Sep 2017Microsoft. (2017, September 15). Backdoor:Win32/Truvasys.A!dha. Retrieved November 30, 2017.
Microsoft Win32Microsoft. (n.d.). Programming reference for the Win32 API. Retrieved March 15, 2020.
Microsoft WinExecMicrosoft. (n.d.). WinExec function. Retrieved September 12, 2024.
Microsoft WinRMMicrosoft. (n.d.). Windows Remote Management. Retrieved September 12, 2024.
Microsoft WinVerifyTrustMicrosoft. (n.d.). WinVerifyTrust function. Retrieved January 31, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.