ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
OWASP FingerprintingOWASP Wiki. (2018, February 16). OAT-004 Fingerprinting. Retrieved October 20, 2020.
OWASP Top 10OWASP. (2018, February 23). OWASP Top Ten Project. Retrieved April 3, 2018.
OWASP Vuln ScanningOWASP. (n.d.). OAT-014 Vulnerability Scanning. Retrieved October 20, 2020.
OWN-CERT Google App Script 2024L'Hutereau Arnaud. (n.d.). Google Workspace Malicious App Script analysis. Retrieved October 2, 2024.
Objective See Green Lambert for OSX Oct 2021Sandvik, Runa. (2021, October 1). Made In America: Green Lambert for OS X. Retrieved March 21, 2022.
Objective-See MacMa Nov 2021Wardle, P. (2021, November 11). OSX.CDDS (OSX.MacMa). Retrieved June 30, 2022.
ObjectiveSee AppleJeus 2019Patrick Wardle. (2019, October 12). Pass the AppleJeus. Retrieved September 28, 2022.
Obscuresecurity Get-GPPPasswordCampbell, C. (2012, May 24). GPP Password Retrieval with PowerShell. Retrieved April 11, 2018.
Obsidian SSPR Abuse 2023Noah Corradin and Shuyang Wang. (2023, August 1). Behind The Breach: Self-Service Password Reset (SSPR) Abuse in Azure AD. Retrieved March 28, 2024.
Obsidian Security SaaS Ransomware June 2023Obsidian Threat Research Team. (2023, June 6). SaaS Ransomware Observed in the Wild for Sharepoint in Microsoft 365. Retrieved October 5, 2025.
OceanLotus for OS XEddie Lee. (2016, February 17). OceanLotus for OS X - an Application Bundle Pretending to be an Adobe Flash Update. Retrieved July 5, 2017.
Oddvar Moe IFEO APR 2018Moe, O. (2018, April 10). Persistence using GlobalFlags in Image File Execution Options - Hidden from Autoruns.exe. Retrieved June 27, 2018.
Oddvar Moe RunOnceEx Mar 2018Moe, O. (2018, March 21). Persistence using RunOnceEx - Hidden from Autoruns.exe. Retrieved June 29, 2018.
Offensive Security VNC Authentication CheckOffensive Security. (n.d.). VNC Authentication. Retrieved October 6, 2021.
Office 265 Azure Domain AvailabilityMicrosoft. (2017, January 23). (Cloud) Tip of the Day: Advanced way to check domain availability for Office 365 and Azure. Retrieved May 27, 2022.
Office 365 Delegated AdministrationMicrosoft. (n.d.). Partners: Offer delegated administration. Retrieved May 27, 2022.
OilRig ISMAgent July 2017Falcone, R. and Lee, B. (2017, July 27). OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group. Retrieved January 8, 2018.
OilRig New Delivery Oct 2017Falcone, R. and Lee, B. (2017, October 9). OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan. Retrieved January 8, 2018.
OilRig Uses Updated BONDUPDATER to Target Middle Eastern GovernmentKyle Wilhoit, Robert Falcone. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved July 21, 2025.
Okta Conditional Access PoliciesOkta. (2023, November 30). Conditional Access Based on Device Security Posture. Retrieved January 2, 2024.
Okta Cross-Tenant Impersonation 2023Okta Defensive Cyber Operations. (2023, August 31). Cross-Tenant Impersonation: Prevention and Detection. Retrieved February 15, 2024.
Okta Scatter Swine 2022Okta. (2022, August 25). Detecting Scatter Swine: Insights into a Relentless Phishing Campaign. Retrieved February 24, 2023.
Oligo ShadowRay Campaign MAR 2024Lumelsly, A. et al. (2024, March 26). ShadowRay: First Known Attack Campaign Targeting AI Workloads Actively Exploited In The Wild. Retrieved December 2, 2024.
Olympic DestroyerPaul Rascagneres, Martin Lee. (2018, February 26). Who Wasn’t Responsible for Olympic Destroyer?. Retrieved June 14, 2025.
Onion RoutingWikipedia. (n.d.). Onion Routing. Retrieved October 20, 2020.
Open Login Items AppleApple. (n.d.). Open items automatically when you log in on Mac. Retrieved October 1, 2021.
OpenAI-CTIOpenAI. (2024, February 14). Disrupting malicious uses of AI by state-affiliated threat actors. Retrieved September 12, 2024.
Operating with EmPyrervrsh3ll. (2016, May 18). Operating with EmPyre. Retrieved July 12, 2017.
Operation Emmentalbotconf eu. (2014, December 31). David Sancho - Finding Holes in Banking 2FA: Operation Emmental. Retrieved January 4, 2024.
Operation Quantum EntanglementHaq, T., Moran, N., Vashisht, S., Scott, M. (2014, September). OPERATION QUANTUM ENTANGLEMENT. Retrieved November 17, 2024.
Optiv Device Code Phishing 2021Optiv. (2021, August 17). Microsoft 365 OAuth Device Code Flow and Phishing. Retrieved March 19, 2024.
Orange Residential ProxiesOrange Cyberdefense. (2024, March 14). Unveiling the depths of residential proxies providers. Retrieved April 11, 2024.
Osanda Stealing NetNTLM HashesOsanda Malith Jayathissa. (2017, March 24). Places of Interest in Stealing NetNTLM Hashes. Retrieved January 26, 2018.
Ossmann Star Feb 2011Michael Ossmann. (2011, February 17). Throwing Star LAN Tap. Retrieved March 30, 2018.
OutFlank System Callsde Plaa, C. (2019, June 19). Red Team Tactics: Combining Direct System Calls and sRDI to bypass AV/EDR. Retrieved September 29, 2021.
Outflank MotW 2020Hegt, S. (2020, March 30). Mark-of-the-Web from a red team’s perspective. Retrieved February 22, 2021.
Outlflank HTML Smuggling 2018Hegt, S. (2018, August 14). HTML smuggling explained. Retrieved May 20, 2021.
Outlook File SizesN. O'Bryan. (2018, May 30). Managing Outlook Cached Mode and OST File Sizes. Retrieved February 19, 2020.
Outpost24Stijn Vande Casteele. (2025, March 31). How to analyze metadata and hide it from hackers. Retrieved July 2, 2025.
PAM Backdoorzephrax. (2018, August 3). linux-pam-backdoor. Retrieved June 25, 2020.
PAM CredsFernández, J. M. (2018, June 27). Exfiltrating credentials via PAM backdoors & DNS requests. Retrieved November 17, 2024.
PAN DNS TunnelingPalo Alto Networks. (n.d.). What Is DNS Tunneling?. Retrieved March 15, 2020.
PCMag DoubleExtensionPCMag. (n.d.). Encyclopedia: double extension. Retrieved August 4, 2021.
PCMag FakeLoginKan, M. (2019, October 24). Hackers Try to Phish United Nations Staffers With Fake Login Pages. Retrieved October 20, 2020.
PTRACE manKerrisk, M. (2020, February 9). PTRACE(2) - Linux Programmer's Manual. Retrieved February 21, 2020.
PTSecurity Cobalt Dec 2016Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.
PTSecurity Cobalt Group Aug 2017Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.
PTSecurity Higaisa 2020PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.
PUAs Unicode - EriksenCharlie Eriksen. (2025, May 13). You're Invited: Delivering malware via Google Calendar invites and PUAs. Retrieved April 21, 2026.
PWC Cloud Hopper April 2017PwC and BAE Systems. (2017, April). Operation Cloud Hopper. Retrieved April 5, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.