ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Slack Security RisksMichael Osakwe. (2020, November 18). 4 SaaS and Slack Security Risks to Consider. Retrieved March 17, 2023.
Sleep, shut down, hibernateAVG. (n.d.). Should You Shut Down, Sleep or Hibernate Your PC or Mac Laptop?. Retrieved June 8, 2023.
Slideshare Abusing SSHDuarte, H., Morrison, B. (2012). (Mis)trusting and (ab)using ssh. Retrieved January 8, 2018.
Slowik Sandworm 2021Joseph Slowik, DomainTools. (2021, March 3). Centreon to Exim and Back: On the Trail of Sandworm. Retrieved April 6, 2024.
SocGholish-updateAndrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.
Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.
Socket Contagious Interview NPM April 2025Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.
Socket GlassWorm January 2026Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.
Socket HexEval BeaverTail Contagious Interview June 2025Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.
Socket Shai-Hulud November 2025Socket Research Team. (2025, November 24). Shai Hulud Strikes Again (v2). Retrieved April 9, 2026.
Socket Shai-Hulud Trufflehog September 2025Socket Research Team. (2025, September 15). Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages. Retrieved April 9, 2026.
Sofacy DealersChoiceFalcone, R. (2018, March 15). Sofacy Uses DealersChoice to Target European Government Agency. Retrieved June 4, 2018.
Sofacy Komplex TrojanDani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.
Softpedia MinerCCimpanu, C.. (2016, September 9). Cryptocurrency Mining Malware Discovered Targeting Seagate NAS Hard Drives. Retrieved September 12, 2024.
Sogeti CERT ESEC Babuk March 2021Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.
SolarWinds Advisory Dec 2020SolarWinds. (2020, December 24). SolarWinds Security Advisory. Retrieved February 22, 2021.
SolarWinds Sunburst Sunspot Update January 2021Sudhakar Ramakrishna . (2021, January 11). New Findings From Our Investigation of SUNBURST. Retrieved January 13, 2021.
SonicWallSecurityNews. (2024, July 12). Disarming DarkGate: A Deep Dive into Thwarting the Latest DarkGate Variant. Retrieved September 22, 2025.
Sood and EnbodyAditya Sood and Richard Enbody. (2014, December 16). Targeted Cyber Attacks. Retrieved January 4, 2024.
SophosGabor Szappanos. (2023, May 3). A doubled “Dragon Breath” adds new air to DLL sideloading attacks. Retrieved October 3, 2025.
Sophos AttachmentDucklin, P. (2020, October 2). Serious Security: Phishing without links – when phishers bring along their own web pages. Retrieved October 20, 2020.
Sophos BlackCat Jul 2022Brandt, Andrew. (2022, July 14). BlackCat ransomware attacks not merely a byproduct of bad luck. Retrieved December 20, 2022.
Sophos Evilginx MAR 2025Everts, M. (2025, March 28). Stealing user credentials with evilginx. Retrieved January 27, 2026.
Sophos Geolocation 2016Wisniewski, C. (2016, May 3). Location-based threats: How cybercriminals target you based on where you live. Retrieved April 1, 2021.
Sophos GootloaderSzappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.
Sophos Maze VM September 2020Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.
Sophos Mustang Panda PLUGXSecureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.
Sophos Netwalker May 2020Szappanos, G., Brandt, A.. (2020, May 27). Netwalker ransomware tools give insight into threat actor. Retrieved May 27, 2020.
Sophos New Ryuk Attack October 2020Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.
Sophos PlugX September 2022Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.
Sophos PowerShell Command History ForensicsVikas, S. (2020, August 26). PowerShell Command History Forensics. Retrieved November 17, 2024.
Sophos PowerShell command auditjak. (2020, June 27). Live Discover - PowerShell command audit. Retrieved August 21, 2020.
Sophos Qilin MSP APR 2025Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.
Sophos Ragnar May 2020SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.
Sophos Safe Mode BootAndrew Brandt. (2019, December 9). Snatch ransomware reboots PCs into Safe Mode to bypass protection. Retrieved April 15, 2026.
Sophos SamSam Apr 2018 Palotay, D. and Mackenzie, P. (2018, April). SamSam Ransomware Chooses Its Targets Carefully. Retrieved April 15, 2019.
Sophos ZeroAccessWyke, J. (2012, April). ZeroAccess. Retrieved July 18, 2016.
SophosGnGal_SystemBC_Dec2020Gallagher, S., Gn, S. (2020, December 16). Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor. Retrieved May 16, 2025.
Sourceforge Heyoka 2022Sourceforge. (n.d.). Heyoka POC Exfiltration Tool. Retrieved October 11, 2022.
Specter Ops - Cloud Credential StorageMaddalena, C.. (2018, September 12). Head in the Clouds. Retrieved October 4, 2019.
SpecterOps AWS Traffic MirroringLuke Paine. (2020, March 11). Through the Looking Glass — Part 1. Retrieved March 17, 2022.
SpecterOps Azure Privilege EscalationAndy Robbins. (2021, October 12). Azure Privilege Escalation via Service Principal Abuse. Retrieved April 1, 2022.
SpecterOps Certified Pre OwnedSchroeder, W. & Christensen, L. (2021, June 22). Certified Pre-Owned - Abusing Active Directory Certificate Services. Retrieved August 2, 2022.
SpecterOps JXA 2020Pitt, L. (2020, August 6). Persistent JXA. Retrieved April 14, 2021.
SpecterOps Lateral Movement from Azure to On-Prem AD 2020Andy Robbins. (2020, August 17). Death from Above: Lateral Movement from Azure to On-Prem AD. Retrieved March 13, 2023.
SpecterOps Managed Identity 2022Andy Robbins. (2022, June 6). Managed Identity Attack Paths, Part 1: Automation Accounts. Retrieved March 18, 2025.
SpectorOps Bifrost Kerberos macOS 2019Cody Thomas. (2019, November 14). When Kirbi walks the Bifrost. Retrieved October 6, 2021.
SpectorOps Code Signing Dec 2017Graeber, M. (2017, December 22). Code Signing Certificate Cloning Attacks and Defenses. Retrieved April 3, 2018.
SpectorOps Hiding Reg Jul 2017Reitz, B. (2017, July 14). Hiding Registry keys with PSReflect. Retrieved August 9, 2018.
SpectorOps Host-Based Jul 2017Atkinson, J. (2017, July 18). Host-based Threat Modeling & Indicator Design. Retrieved March 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.