Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Ars Technica GRU indictment Jul 2018 | Gallagher, S. (2018, July 27). How they did it (and will likely try again): GRU hackers vs. US elections. Retrieved September 13, 2018. |
| Ars Technica VMWare Code Execution Vulnerability 2021 | Dan Goodin . (2021, February 25). Code-execution flaw in VMware has a severity rating of 9.8 out of 10. Retrieved April 8, 2025. |
| ArsTechnica Great Firewall of China | Goodin, D.. (2015, March 31). Massive denial-of-service attack on GitHub tied to Chinese government. Retrieved April 19, 2019. |
| ArsTechnica Intel | Goodin, D. & Salter, J. (2020, August 6). More than 20GB of Intel source code and proprietary data dumped online. Retrieved October 20, 2020. |
| Artic Wolf Kali365 Device Code OAuth June 2026 | Artic Wolf Labs. (2026, June 2). Retrieved July 30, 2026. |
| Artic Wolf Labs Kali365 Device Code April 2026 | Artic Wolf Labs. (2026, April 24). Token Bingo: Don’t Let Your Code be the Winner. Retrieved July 30, 2026. |
| Arxiv Avaddon Feb 2021 | Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021. |
| Aryaka Kimsuky July 2025 | Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026. |
| AsyncRAT GitHub | Nyan-x-Cat. (n.d.). NYAN-x-CAT / AsyncRAT-C-Sharp. Retrieved October 3, 2023. |
| Atlas SEO | Atlas Cybersecurity. (2021, April 19). Threat Actors use Search-Engine-Optimization Tactics to Redirect Traffic and Install Malware. Retrieved September 30, 2022. |
| Attackify Rundll32.exe Obscurity | Attackify. (n.d.). Rundll32.exe Obscurity. Retrieved August 23, 2021. |
| Attacking VNC Servers PentestLab | Administrator, Penetration Testing Lab. (2012, October 30). Attacking VNC Servers. Retrieved October 6, 2021. |
| Australia ‘Evil Twin’ | Toulas, Bill. (2024, July 1). Australian charged for ‘Evil Twin’ WiFi attack on plane. Retrieved September 17, 2024. |
| Auth0 - Why You Should Always Use Access Tokens to Secure APIs Sept 2019 | Auth0. (n.d.). Why You Should Always Use Access Tokens to Secure APIs. Retrieved September 12, 2019. |
| Auth0 Understanding Refresh Tokens | Auth0 Inc.. (n.d.). Understanding Refresh Tokens. Retrieved November 17, 2024. |
| AutoHotKey | AutoHotkey Foundation LLC. (n.d.). Using the Program. Retrieved March 29, 2024. |
| AutoIT | AutoIT. (n.d.). Running Scripts. Retrieved March 29, 2024. |
| Avaddon Ransomware 2021 | Javier Yuste and Sergio Pastrana. (2021). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved March 24, 2025. |
| Avast CCleaner3 2018 | Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018. |
| Avast RaspberryRobin 2022 | Jan Vojtěšek. (2022, September 22). Raspberry Robin’s Roshtyak: A Little Lesson in Trickery. Retrieved May 17, 2024. |
| Avertium Black Basta June 2022 | Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023. |
| Avertium Storm-0501 Sabbath Ransomware Arcane January 2022 | Avertium. (2022, January 11). An In-Depth Look at Ransomware Gang, Sabbath. Retrieved October 19, 2025. |
| Avertium callback phishing | Avertium. (n.d.). EVERYTHING YOU NEED TO KNOW ABOUT CALLBACK PHISHING. Retrieved February 2, 2023. |
| Avira Mustang Panda January 2020 | Hamzeloofard, S. (2020, January 31). New wave of PlugX targets Hong Kong | Avira Blog. Retrieved April 13, 2021. |
| Awake Security Avaddon | Gahlot, A. (n.d.). Threat Hunting for Avaddon Ransomware. Retrieved August 19, 2021. |
| Awake Security C2 Cloud | Gary Golomb and Tory Kei. (n.d.). Threat Hunting Series: Detecting Command & Control in the Cloud. Retrieved May 27, 2022. |
| Awesome Executable Packing | Alexandre D'Hondt. (n.d.). Awesome Executable Packing. Retrieved March 11, 2022. |
| Azure - Resource Manager API | Microsoft. (2019, May 20). Azure Resource Manager. Retrieved June 17, 2020. |
| Azure - Stormspotter | Microsoft. (2020). Azure Stormspotter GitHub. Retrieved June 17, 2020. |
| Azure AD Conditional Access Exclusions | Microsoft. (2022, August 26). Use Azure AD access reviews to manage users excluded from Conditional Access policies. Retrieved August 30, 2022. |
| Azure AD Connect for Read Teamers | Adam Chester. (2019, February 18). Azure AD Connect for Red Teamers. Retrieved September 28, 2022. |
| Azure AD Federation Vulnerability | Dr. Nestori Syynimaa.. (2017, November 16). Security vulnerability in Azure AD & Office 365 identity federation. Retrieved February 1, 2022. |
| Azure AD Graph API | Microsoft. (2016, March 26). Operations overview | Graph API concepts. Retrieved June 18, 2020. |
| Azure AD Hybrid Identity | Microsoft. (2022, August 26). Choose the right authentication method for your Azure Active Directory hybrid identity solution. Retrieved September 28, 2022. |
| Azure AD Recon | Dr. Nestori Syynimaa. (2020, June 13). Just looking: Azure Active Directory reconnaissance as an outsider. Retrieved February 1, 2022. |
| Azure Active Directory Reconnaisance | Dr. Nestori Syynimaa. (2020, June 13). Just looking: Azure Active Directory reconnaissance as an outsider. Retrieved May 27, 2022. |
| Azure Just in Time Access 2023 | Microsoft. (2023, August 29). Configure and approve just-in-time access for Azure Managed Applications. Retrieved September 21, 2023. |
| Azure Serial Console | Microsoft. (2022, October 17). Azure Serial Console. Retrieved June 2, 2023. |
| Azure Storage Lifecycles | Microsoft Azure. (2024, July 3). Configure a lifecycle management policy. Retrieved September 25, 2024. |
| Azure Update Virtual Machines | Microsoft. (n.d.). Virtual Machines - Update. Retrieved April 1, 2022. |
| Azure Virtual Network TAP | Microsoft. (2022, February 9). Virtual network TAP. Retrieved March 17, 2022. |
| BATLOADER: The Evasive Downloader Malware | Bethany Hardin, Lavine Oluoch, Tatiana Vollbrecht. (2022, November 14). BATLOADER: The Evasive Downloader Malware. Retrieved June 5, 2023. |
| BBC LAPSUS Apr 2022 | BBC. (2022, April 1). LAPSUS: Two UK Teenagers Charged with Hacking for Gang. Retrieved June 9, 2022. |
| BBC-Ronin | Joe Tidy. (2022, March 30). Ronin Network: What a $600m hack says about the state of crypto. Retrieved August 18, 2023. |
| BBC-malvertising | BBC. (2011, March 29). Spotify ads hit by malware attack. Retrieved February 21, 2023. |
| BH Linux Inject | Colgan, T. (2015, August 15). Linux-Inject. Retrieved February 21, 2020. |
| BH Manul Aug 2016 | Galperin, E., Et al.. (2016, August 4). When Governments Attack: State Sponsored Malware Attacks Against Activists, Lawyers, and Journalists. Retrieved May 23, 2018. |
| BOA Telephone Scams | Bank of America. (n.d.). How to avoid telephone scams. Retrieved September 8, 2023. |
| BOHOPS Abusing the COM Registry | BOHOPS. (2018, August 18). Abusing the COM Registry Structure (Part 2): Hijacking & Loading Techniques. Retrieved August 10, 2020. |
| Backdooring an AWS account | Daniel Grzelak. (2016, July 9). Backdooring an AWS account. Retrieved May 27, 2022. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.