Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023 | Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025. |
| Palo Alto VOID MANTICORE Iran Cyber Threats March 2026 | Justin Moore. (2026, March 16). Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization. Retrieved April 20, 2026. |
| Palo Alto menuPass Feb 2017 | Miller-Osborn, J. and Grunzweig, J.. (2017, February 16). menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations. Retrieved March 1, 2017. |
| PaloAlto 3102 Sept 2015 | Falcone, R. & Miller-Osborn, J. (2015, September 23). Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media. Retrieved March 19, 2018. |
| PaloAlto CardinalRat Apr 2017 | Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018. |
| PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023 | Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025. |
| PaloAlto DNS Requests May 2016 | Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018. |
| PaloAlto EncodedCommand March 2017 | White, J. (2017, March 10). Pulling Back the Curtains on EncodedCommand PowerShell Attacks. Retrieved February 12, 2018. |
| PaloAlto MUSTANG PANDA PUBLOAD MARCH 2024 | Unit42. (2024, March 26). ASEAN Entities in the Spotlight: Chinese APT Group Targeting. Retrieved August 4, 2025. |
| PaloAlto NanoCore Feb 2016 | Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018. |
| PaloAlto Patchwork Mar 2018 | Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018. |
| PaloAlto StrelaStealer 2024 | Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya & Vishwa Thothathri, Palo Alto Networks. (2024, March 22). Large-Scale StrelaStealer Campaign in Early 2024. Retrieved December 31, 2024. |
| PaloAlto UBoatRAT Nov 2017 | Hayashi, K. (2017, November 28). UBoatRAT Navigates East Asia. Retrieved January 12, 2018. |
| PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024 | Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025. |
| Pass The Cookie | Rehberger, J. (2018, December). Pivot to the Cloud using Pass the Cookie. Retrieved April 5, 2019. |
| PassLib mscache | Eli Collins. (2016, November 25). Windows' Domain Cached Credentials v2. Retrieved February 21, 2020. |
| Passcape LSA Secrets | Passcape. (n.d.). Windows LSA secrets. Retrieved February 21, 2020. |
| Password Protected Word Docs | Lawrence Abrams. (2017, July 12). PSA: Don't Open SPAM Containing Password Protected Word Docs. Retrieved January 5, 2022. |
| Pastebin EchoSec | Ciarniello, A. (2019, September 24). What is Pastebin and Why Do Hackers Love It?. Retrieved April 11, 2023. |
| PaypalScam | Bob Sullivan. (2000, July 24). PayPal alert! Beware the 'PaypaI' scam. Retrieved March 2, 2017. |
| PegasusCitizenLab | Bill Marczak and John Scott-Railton. (2016, August 24). The Million Dollar Dissident: NSO Group’s iPhone Zero-Days used against a UAE Human Rights Defender. Retrieved December 12, 2016. |
| Peirates GitHub | InGuardians. (2022, January 5). Peirates GitHub. Retrieved February 8, 2022. |
| PenTestLabs AppDomainManagerInject | Administrator. (2020, May 26). APPDOMAINMANAGER INJECTION AND DETECTION. Retrieved March 28, 2024. |
| Penetration Testing Lab MSXSL July 2017 | netbiosX. (2017, July 6). AppLocker Bypass – MSXSL. Retrieved July 3, 2018. |
| Pentera vCenter Information Disclosure | Yuval Lazar. (2022, March 29). Mitigating VMware vCenter Information Disclosure. Retrieved March 26, 2025. |
| Pentesting AD Forests | García, C. (2019, April 3). Pentesting Active Directory Forests. Retrieved October 20, 2020. |
| Pentestlab Stored Credentials | netbiosX. (2017, April 19). Stored Credentials. Retrieved April 6, 2018. |
| Pentestlab Token Manipulation | netbiosX. (2017, April 3). Token Manipulation. Retrieved April 21, 2017. |
| Pepe Berba Systemd 2022 | Pepe Berba. (2022, February 7). Hunting for Persistence in Linux (Part 5): Systemd Generators. Retrieved April 8, 2025. |
| Perception Point | Arthur Vaiselbuh, Peleg Cabra. (2024, November 7). Evasive ZIP Concatenation: Trojan Targets Windows Users. Retrieved March 3, 2025. |
| Perez Sitemap XML 2023 | Adi Perez. (2023, February 22). How Attackers Can Misuse Sitemaps to Enumerate Users and Discover Sensitive Information. Retrieved July 18, 2024. |
| Peripheral Discovery Linux | Shahriar Shovon. (2018, March). List USB Devices Linux. Retrieved March 11, 2022. |
| Peripheral Discovery macOS | SS64. (n.d.). system_profiler. Retrieved March 11, 2022. |
| Permiso GUI-Vil 2023 | Ian Ahl. (2023, May 22). Unmasking GUI-Vil: Financially Motivated Cloud Threat Actor. Retrieved August 30, 2024. |
| Permiso SES Abuse 2023 | Nathan Eades. (2023, January 12). SES-pionage. Retrieved September 25, 2024. |
| Permiso Scattered Spider 2023 | Ian Ahl. (2023, September 20). LUCR-3: SCATTERED SPIDER GETTING SAAS-Y IN THE CLOUD. Retrieved September 25, 2023. |
| PersistentJXA_leopitt | Leo Pitt. (2020, August 6). Persistent JXA - A poor man's Powershell for macOS. Retrieved January 11, 2021. |
| Petri Logon Script AD | Daniel Petri. (2009, January 8). Setting up a Logon Script through Active Directory Users and Computers in Windows Server 2008. Retrieved November 15, 2019. |
| Pfammatter - Hidden Inbox Rules | Damian Pfammatter. (2018, September 17). Hidden Inbox Rules in Microsoft Exchange. Retrieved October 12, 2021. |
| Phish Labs Silent Librarian | Hassold, Crane. (2018, March 26). Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment. Retrieved February 3, 2021. |
| Phoenix TeamPCP 20 MAY 2026 | Webb, M. (2026, May 20). TeamPCP Wave Four: GitHub Breach via Poisoned VS Code Extension, durabletask PyPI Worm, and ~4,000 Internal Repositories Exfiltrated. Retrieved July 16, 2026. |
| Picus BlackByte 2022 | Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024. |
| Picus Emotet Dec 2018 | Özarslan, S. (2018, December 21). The Christmas Card you never wanted - A new wave of Emotet is back to wreak havoc. Retrieved March 25, 2019. |
| Picus Labs Proc cump 2022 | Huseyin Can YUCEEL & Picus Labs. (2022, March 22). Retrieved March 31, 2023. |
| Picus Qilin MAR 2025 | Hacioglu, S. (2025, March 10). Qilin Ransomware: Exposing the TTPs Behind One of the Most Active Ransomware Campaigns of 2024. Retrieved September 26, 2025. |
| Picus Security BRICKSTORM UNC5221 October 2025 | Huseyin Can Yuceel. (2025, October 1). BRICKSTORM Malware: UNC5221 Targets Tech and Legal Sectors in the United States. Retrieved April 16, 2026. |
| Picus Security UNC5221 Ivanti May 2025 | Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026. |
| Picus Sodinokibi January 2020 | Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020. |
| Pincus Emotet 2020 | Süleyman Özarslan, PhD; Pincus Security Inc.. (2020, July 14). An Analysis of Emotet Malware: PowerShell Unobfuscation. Retrieved November 25, 2024. |
| Podman Systemd | Valentin Rothberg. (2022, March 16). How to run pods as systemd services with Podman. Retrieved February 15, 2024. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.