Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| SekoiaBourhis_DiceLoader_Feb2024 | Bourhis, P., Sekoia TDR. (2024, February 1). Unveiling the intricacies of DiceLoader. Retrieved May 14, 2025. |
| SensePost MacroLess DDE Oct 2017 | Stalmans, E., El-Sherei, S. (2017, October 9). Macro-less Code Exec in MSWord. Retrieved November 21, 2017. |
| SensePost NotRuler | SensePost. (2017, September 21). NotRuler - The opposite of Ruler, provides blue teams with the ability to detect Ruler usage against Exchange. Retrieved February 4, 2019. |
| SensePost Outlook Forms | Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019. |
| SensePost Outlook Home Page | Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019. |
| SensePost PS DDE May 2016 | El-Sherei, S. (2016, May 20). PowerShell, C-Sharp and DDE The Power Within. Retrieved November 22, 2017. |
| SensePost Ruler GitHub | SensePost. (2016, August 18). Ruler: A tool to abuse Exchange services. Retrieved February 4, 2019. |
| Sentinel Labs | Phil Stokes. (2021, January 11). FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts. Retrieved September 30, 2022. |
| Sentinel Labs LockBit 3.0 JUL 2022 | Walter, J. (2022, July 21). LockBit 3.0 Update | Unpicking the Ransomware’s Latest Anti-Analysis and Evasion Techniques. Retrieved February 5, 2025. |
| Sentinel Labs NullBulge 2024 | Jim Walter. (2024, July 16). NullBulge | Threat Actor Masquerades as Hacktivist Group Rebelling Against AI. Retrieved August 30, 2024. |
| Sentinel Labs Top Tier Target 2025 | Tom Hegel, Aleksandar Milenkoski & Jim Walter. (2025, April 28). Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries. Retrieved May 22, 2025. |
| Sentinel Labs WastedLocker July 2020 | Walter, J.. (2020, July 23). WastedLocker Ransomware: Abusing ADS and NTFS File Attributes. Retrieved September 14, 2021. |
| Sentinel One Contagious Interview ClickFix September 2025 | Aleksandar Milenkoski, Sreekar Madabushi, Kenneth Kinion. (2025, September 4). Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms. Retrieved October 20, 2025. |
| Sentinel One Tainted Love 2023 | Aleksandar Milenkoski, Juan Andres Guerrero-Saade, and Joey Chen. (2023, March 23). Operation Tainted Love | Chinese APTs Target Telcos in New Attacks. Retrieved March 18, 2025. |
| SentinelLabs Agent Tesla Aug 2020 | Walter, J. (2020, August 10). Agent Tesla | Old RAT Uses New Tricks to Stay on Top. Retrieved December 11, 2020. |
| SentinelLabs Metador Sept 2022 | Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023. |
| SentinelLabs Metador Technical Appendix Sept 2022 | SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023. |
| SentinelLabs SNS Sender 2024 | Alex Delamotte. (2024, February 15). SNS Sender | Active Campaigns Unleash Messaging Spam Through the Cloud. Retrieved September 25, 2024. |
| SentinelLabs macOS Malware 2021 | Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved May 22, 2025. |
| SentinelLabs reversing run-only applescripts 2021 | Phil Stokes. (2021, January 11). FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts. Retrieved September 29, 2022. |
| SentinelOne AcidPour 2024 | Juan Andrés Guerrero-Saade & Tom Hegel. (2024, March 21). AcidPour | New Embedded Wiper Variant of AcidRain Appears in Ukraine. Retrieved November 25, 2024. |
| SentinelOne Agrius 2021 | Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024. |
| SentinelOne Aoqin Dragon June 2022 | Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022. |
| SentinelOne AppleScript | Phil Stokes. (2020, March 16). How Offensive Actors Use AppleScript For Attacking macOS. Retrieved July 17, 2020. |
| SentinelOne Cuckoo Stealer May 2024 | Stokes, P. (2024, May 9). macOS Cuckoo Stealer | Ensuring Detection and Defense as New Samples Rapidly Emerge. Retrieved August 20, 2024. |
| SentinelOne FrameworkPOS September 2019 | Kremez, V. (2019, September 19). FIN6 “FrameworkPOS”: Point-of-Sale Malware Analysis & Internals. Retrieved September 8, 2020. |
| SentinelOne Gootloader June 2021 | Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024. |
| SentinelOne Hermetic Wiper February 2022 | Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022. |
| SentinelOne INC Ransomware | SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024. |
| SentinelOne Lazarus macOS July 2020 | Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020. |
| SentinelOne LockBit 2.0 | SentinelOne. (n.d.). LockBit 2.0: In-Depth Analysis, Detection, Mitigation, and Removal. Retrieved January 24, 2025. |
| SentinelOne MacMa Nov 2021 | Stokes, P. (2021, November 15). Infect If Needed | A Deeper Dive Into Targeted Backdoor macOS.Macma. Retrieved June 30, 2022. |
| SentinelOne Macma 2021 | Phil Stokes. (2021, November 15). Infect If Needed | A Deeper Dive Into Targeted Backdoor macOS.Macma. Retrieved July 26, 2024. |
| SentinelOne NobleBaron June 2021 | Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021. |
| SentinelOne Qilin NOV 2022 | SentinelOne. (2022, November 30). Agenda (Qilin). Retrieved September 26, 2025. |
| SentinelOne SocGholish Infrastructure November 2022 | Milenkoski, A. (2022, November 7). SocGholish Diversifies and Expands Its Malware Staging Infrastructure to Counter Defenders. Retrieved March 22, 2024. |
| SentinelOne ToolShell JUL 2025 | Kenin, S. et al. (2025, July 21). SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers. Retrieved October 15, 2025. |
| SentinelOne Valak June 2020 | Reaves, J. and Platt, J. (2020, June). Valak Malware and the Connection to Gozi Loader ConfCrew. Retrieved August 31, 2020. |
| SentinelOne WinterVivern 2023 | Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024. |
| SentinelOne macOS Red Team | Phil Stokes. (2019, December 5). macOS Red Team: Calling Apple APIs Without Building Binaries. Retrieved July 17, 2020. |
| Shadowserver Strategic Web Compromise | Adair, S., Moran, N. (2012, May 15). Cyber Espionage & Strategic Web Compromises – Trusted Websites Serving Dangerous Results. Retrieved March 13, 2018. |
| Shlayer jamf gatekeeper bypass 2021 | Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021. |
| Shodan | Shodan. (n.d.). Shodan. Retrieved October 20, 2020. |
| Shortcut for Persistence | Elastic. (n.d.). Shortcut File Written or Modified for Persistence. Retrieved June 1, 2022. |
| SigmaHQ | Sittikorn S. (2022, April 15). Removal Of SD Value to Hide Schedule Task - Registry. Retrieved June 1, 2022. |
| SilentBreak Offensive PS Dec 2015 | Christensen, L.. (2015, December 28). The Evolution of Offensive PowerShell Invocation. Retrieved December 8, 2018. |
| SilentBreak Outlook Rules | Landers, N. (2015, December 4). Malicious Outlook Rules. Retrieved February 4, 2019. |
| SilentPush_GamaredonFastFlux_Sept2023 | Silent Push. (2023, September 7). From Russia with a 71: Uncovering Gamaredon's fast flux infrastructure. New Apex domains and ASN/IP diversity patterns discovered. Retrieved July 28, 2025. |
| SingHealth Breach Jan 2019 | Committee of Inquiry into the Cyber Attack on SingHealth. (2019, January 10). Public Report of the Committee of Inquiry into the Cyber Attack on Singapore Health Services Private Limited's Patient Database. Retrieved June 29, 2020. |
| Sixdub PowerPick Jan 2016 | Warner, J.. (2015, January 6). Inexorable PowerShell – A Red Teamer’s Tale of Overcoming Simple AppLocker Policies. Retrieved December 8, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.