ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Microsoft Window ClassesMicrosoft. (n.d.). About Window Classes. Retrieved December 16, 2017.
Microsoft Windows ScriptsMicrosoft. (2017, January 18). Windows Script Interfaces. Retrieved June 23, 2020.
Microsoft Windows Startup SettingsMicrosoft. (n.d.). Retrieved April 15, 2026.
Microsoft Wingbird Nov 2017Microsoft. (2017, November 9). Backdoor:Win32/Wingbird.A!dha. Retrieved November 27, 2017.
Microsoft Winnti Jan 2017Cap, P., et al. (2017, January 25). Detecting threat actors in recent German industrial attacks with Windows Defender ATP. Retrieved February 8, 2017.
Microsoft Wow6432Node 2018Microsoft. (2018, May 31). 32-bit and 64-bit Application Data in the Registry. Retrieved August 3, 2020.
Microsoft XSLT Script Mar 2017Wenzel, M. et al. (2017, March 30). XSLT Stylesheet Scripting Using <msxsl:script>. Retrieved July 3, 2018.
Microsoft XorDdos Linux Stealth 2022Microsoft Threat Intelligence. (2022, May 19). Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices. Retrieved September 27, 2023.
Microsoft Zone.Identifier 2020Microsoft. (2020, August 31). Zone.Identifier Stream Name. Retrieved February 22, 2021.
Microsoft _VBA_PROJECT StreamMicrosoft. (2020, February 19). 2.3.4.1 _VBA_PROJECT Stream: Version Dependent Project Information. Retrieved September 18, 2020.
Microsoft about_HistoryMicrosoft. (2024, January 19). about_History. Retrieved June 13, 2025.
Microsoft about_History prevent command historyMicrosoft. (n.d.). Retrieved April 15, 2026.
Microsoft attrib 2023Xelu86, et al. (2023, September 25). attrib. Retrieved November 22, 2024.
Microsoft auditpolMicrosoft. (n.d.). Retrieved April 15, 2026.
Microsoft bcdeditMicrosoft. (n.d.). Retrieved April 15, 2026.
Microsoft getglobaladdresslistMicrosoft. (n.d.). Get-GlobalAddressList. Retrieved October 6, 2019.
Microsoft gpresultMicrosoft. (2017, October 16). gpresult. Retrieved August 6, 2021.
Microsoft msiexecMicrosoft. (2017, October 15). msiexec. Retrieved January 24, 2020.
Microsoft msolrolememberMicrosoft. (n.d.). Get-MsolRoleMember. Retrieved October 6, 2019.
Microsoft msxsl.exeMicrosoft. (n.d.). Command Line Transformation Utility (msxsl.exe). Retrieved July 3, 2018.
Microsoft odbcconf.exeMicrosoft. (2017, January 18). ODBCCONF.EXE. Retrieved March 7, 2019.
Microsoft redirectionMicrosoft. (2023, October 12). Dynamic-link library redirection. Retrieved January 30, 2025.
Microsoft xp_cmdshell 2017Microsoft. (2017, March 15). xp_cmdshell (Transact-SQL). Retrieved September 9, 2019.
Microsoft: Powercfg command-line optionsMicrosoft. (2021, December 15). Powercfg command-line options. Retrieved June 5, 2023.
Microsoft_diskpart_Feb2023Microsoft. (2023, February 3). diskpart. Retrieved March 17, 2025.
MimiPenguin GitHub May 2017Gregal, H. (2017, May 12). MimiPenguin. Retrieved December 5, 2017.
Minerva Labs Black Basta May 2022Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.
MitigaAriel Szarf, Doron Karmi, and Lionel Saposnik. (n.d.). Oops, I Leaked It Again — How Mitiga Found PII in Exposed Amazon RDS Snapshots. Retrieved September 24, 2024.
Mitiga Security Advisory: SSM Agent as Remote Access TrojanAriel Szarf, Or Aspir. (n.d.). Mitiga Security Advisory: Abusing the SSM Agent as a Remote Access Trojan. Retrieved January 31, 2024.
Mnemonic misuse visual studioMnemonic. (n.d.). Advisory: Misuse of Visual Studio Code for traffic tunnelling. Retrieved March 30, 2025.
Modexp Windows Process Injectionodzhan. (2019, April 25). Windows Process Injection: WordWarping, Hyphentension, AutoCourgette, Streamception, Oleum, ListPlanting, Treepoline. Retrieved November 15, 2021.
Module Stomping for Shellcode InjectionRed Teaming Experiments. (n.d.). Module Stomping for Shellcode Injection. Retrieved July 14, 2022.
Mondok Windows PiggyBack BITS May 2007Mondok, M. (2007, May 11). Malware piggybacks on Windows’ Background Intelligent Transfer Service. Retrieved January 12, 2018.
Moran 2013Moran, N., & Villeneuve, N. (2013, August 12). Survival of the Fittest: New York Times Attackers Evolve Quickly &#91;Blog&#93;. Retrieved November 17, 2024.
Moran 2014Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group &#91;Blog&#93;. Retrieved November 12, 2014.
Moran RDPiecesMoran, B. (2020, November 18). Putting Together the RDPieces. Retrieved October 17, 2022.
Morphisec Cobalt Gang Oct 2018Gorelik, M. (2018, October 08). Cobalt Group 2.0. Retrieved November 5, 2018.
Morphisec FIN7 June 2017Gorelik, M.. (2017, June 9). FIN7 Takes Another Bite at the Restaurant Industry. Retrieved July 13, 2017.
Morphisec Lokibot April 2020Cheruku, H. (2020, April 15). LOKIBOT WITH AUTOIT OBFUSCATOR + FRENCHY SHELLCODE. Retrieved May 14, 2020.
Morphisec ShellTea June 2019Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019.
Morphisec Snip3 May 2021Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.
MoustachedBouncer ESET August 2023Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.
Mozilla User AgentMDN contributors. (2025, July 4). User-Agent header. Retrieved October 19, 2025.
Mr. D0x BitB 2022mr.d0x. (2022, March 15). Browser In The Browser (BITB) Attack. Retrieved March 8, 2023.
MsitPros CHM Aug 2017Moe, O. (2017, August 13). Bypassing Device guard UMCI using CHM – CVE-2017-8625. Retrieved October 3, 2018.
MuddyWater TrendMicro June 2018Villanueva, M., Co, M. (2018, June 14). Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor. Retrieved July 3, 2018.
Mythc DocumentationThomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.
Mythic GithubThomas, C. (2018, July 4). Mythic. Retrieved March 25, 2022.
Mythic SpecterOpsThomas, C. (2020, August 13). A Change of Mythic Proportions. Retrieved March 25, 2022.
NCC Group APT15 Alive and StrongSmallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.