Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Symantec Ushedix June 2008 | Symantec. (2008, June 28). Trojan.Ushedix. Retrieved December 18, 2017. |
| Symantec Vasport May 2012 | Zhou, R. (2012, May 15). Backdoor.Vasport. Retrieved February 22, 2018. |
| Symantec Volgmer Aug 2014 | Yagi, J. (2014, August 24). Trojan.Volgmer. Retrieved July 16, 2018. |
| Symantec W.32 Stuxnet Dossier | Nicolas Falliere, Liam O. Murchu, Eric Chien. (2011, February). W32.Stuxnet Dossier. Retrieved December 7, 2020. |
| Symantec W32.Duqu | Symantec Security Response. (2011, November). W32.Duqu: The precursor to the next Stuxnet. Retrieved September 17, 2015. |
| Symantec WastedLocker June 2020 | Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021. |
| Symantec Waterbug | Symantec. (2015, January 26). The Waterbug attack group. Retrieved April 10, 2015. |
| Symantec Waterbug Jun 2019 | Symantec DeepSight Adversary Intelligence Team. (2019, June 20). Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments. Retrieved July 8, 2019. |
| Symantec Whitefly March 2019 | Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020. |
| Symantec Wiarp May 2012 | Zhou, R. (2012, May 15). Backdoor.Wiarp. Retrieved February 22, 2018. |
| Symantec Windows Rootkits | Symantec. (n.d.). Windows Rootkit Overview. Retrieved December 21, 2017. |
| SymantecCarbonBlack_Seedworm_Mar2026 | Threat Hunter Team. (2026, March 5). Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company. Retrieved March 5, 2026. |
| SymantecCarbonBlack_ShuckwormUSB_Apr2025 | Threat Hunter Team, Symantec and Carbon Black. (2025, April 10). Shuckworm Targets Foreign Military Mission Based in Ukraine. Retrieved July 23, 2025. |
| Synack Secure Kernel Extension Broken | Wardle, P. (2017, September 8). High Sierra’s ‘Secure Kernel Extension Loading’ is Broken. Retrieved November 17, 2024. |
| Synactiv Hijacking GitHub Runners | Hugo Vincent. (2024, May 22). Hijacking GitHub runners to compromise the organization. Retrieved May 22, 2025. |
| Synes Cyber Corner Malicious Azure Application 2023 | syne0. (2023, July 10). Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise. Retrieved March 20, 2025. |
| Syscall 2014 | Drysdale, D. (2014, July 16). Anatomy of a system call, part 2. Retrieved June 16, 2020. |
| Sysdig Cryptojacking Proxyjacking 2023 | Miguel Hernandez. (2023, August 17). LABRAT: Stealthy Cryptojacking and Proxyjacking Campaign Targeting GitLab . Retrieved September 25, 2024. |
| Sysdig Fileless Malware 23022 | Nicholas Lang. (2022, May 3). Fileless malware mitigation. Retrieved September 24, 2024. |
| Sysdig Kinsing November 2020 | Huang, K. (2020, November 23). Zoom into Kinsing. Retrieved April 1, 2021. |
| Sysdig LLMJacking 2024 | LLMjacking: Stolen Cloud Credentials Used in New AI Attack. (2024, May 6). Alessandro Brucato. Retrieved September 25, 2024. |
| Sysdig Proxyjacking | Crystal Morin. (2023, April 4). Proxyjacking has Entered the Chat. Retrieved July 6, 2023. |
| Sysdig ScarletEel 2.0 | SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. (2023, July 11). SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. Retrieved July 12, 2023. |
| Sysdig ScarletEel 2.0 2023 | Alessandro Brucato. (2023, July 11). SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. Retrieved September 25, 2023. |
| Sysdig TeamPCP MAR 2026 | Sysdig Threat Research Team. (2026, March 23). TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions. Retrieved July 1, 2026. |
| System Information Discovery Technique | YUCEEL, Huseyin Can. Picus Labs. (2022, June 9). The System Information Discovery Technique Explained - MITRE ATT&CK T1082. Retrieved March 27, 2024. |
| System and kernel extensions in macOS | Apple. (n.d.). System and kernel extensions in macOS. Retrieved March 31, 2022. |
| Systemd Remote Control | Aaron Kili. (2018, January 16). How to Control Systemd Services on Remote Linux Server. Retrieved July 26, 2021. |
| Systemd Service Units | Freedesktop.org. (n.d.). systemd.service — Service unit configuration. Retrieved March 16, 2020. |
| Szappanos MgBot 2014 | Gabor Szappanos. (2014, February 3). Needle in a haystack. Retrieved July 25, 2024. |
| T1105: Trellix_search-ms | Mathanraj Thangaraju, Sijo Jacob. (2023, July 26). Beyond File Search: A Novel Method for Exploiting the "search-ms" URI Protocol Handler. Retrieved March 15, 2024. |
| T1562.002_redcanaryco | redcanaryco. (2021, September 3). T1562.002 - Disable Windows Event Logging. Retrieved September 13, 2021. |
| TA571 | Axel F, Selena Larson. (2023, October 30). TA571 Delivers IcedID Forked Loader. Retrieved February 13, 2024. |
| TAG APT42 | Google Threat Analysis Group. (2024, August 14). Iranian backed group steps up phishing campaigns against Israel, U.S.. Retrieved October 9, 2024. |
| TCC Database | Marina Liang. (2024, April 23). Return of the mac(OS): Transparency, Consent, and Control (TCC) Database Manipulation. Retrieved March 28, 2024. |
| TCC macOS bypass | Phil Stokes. (2021, July 1). Bypassing macOS TCC User Privacy Protections By Accident and Design. Retrieved March 21, 2024. |
| TLDP Shared Libraries | The Linux Documentation Project. (n.d.). Shared Libraries. Retrieved January 31, 2020. |
| TLDRSec AWS Attacks | Clint Gibler and Scott Piper. (2021, January 4). Lesser Known Techniques for Attacking AWS Environments. Retrieved March 4, 2024. |
| TP-Link Quad 7 AUG 2025 | TP-Link . (2025, August 29). Technical News and Reports about Quad 7 (7777) Botnet aka CovertNetwork-1658. Retrieved October 10, 2025. |
| Talent-Jump Clambling February 2020 | Chen, T. and Chen, Z. (2020, February 17). CLAMBLING - A New Backdoor Base On Dropbox. Retrieved November 12, 2021. |
| Talos - Cisco Attack 2022 | Nick Biasini. (2022, August 10). Cisco Talos shares insights related to recent cyber attack on Cisco. Retrieved March 9, 2023. |
| Talos Agent Tesla Oct 2018 | Brumaghin, E., et al. (2018, October 15). Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox. Retrieved November 5, 2018. |
| Talos Bisonal 10 Years March 2020 | Warren Mercer, Paul Rascagneres, Vitor Ventura. (2020, March 6). Bisonal 10 Years of Play. Retrieved October 17, 2021. |
| Talos Bisonal Mar 2020 | Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022. |
| Talos CCleanup 2017 | Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018. |
| Talos Cobalt Group July 2018 | Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018. |
| Talos Cobalt Strike September 2020 | Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024. |
| Talos DNSpionage Nov 2018 | Mercer, W., Rascagneres, P. (2018, November 27). DNSpionage Campaign Targets Middle East. Retrieved October 9, 2020. |
| Talos Discord Webhook Abuse | Nick Biasini, Edmund Brumaghin, Chris Neal, and Paul Eubanks. (2021, April 7). https://blog.talosintelligence.com/collab-app-abuse/. Retrieved July 20, 2023. |
| Talos Emotet Jan 2019 | Brumaghin, E.. (2019, January 15). Emotet re-emerges after the holidays. Retrieved March 25, 2019. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.