Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| TechNet How UAC Works | Lich, B. (2016, May 31). How User Account Control Works. Retrieved June 3, 2016. |
| TechNet Inside UAC | Russinovich, M. (2009, July). User Account Control: Inside Windows 7 User Account Control. Retrieved July 26, 2016. |
| TechNet Ipconfig | Microsoft. (n.d.). Ipconfig. Retrieved April 17, 2016. |
| TechNet Logon Scripts | Microsoft. (2005, January 21). Creating logon scripts. Retrieved April 27, 2016. |
| TechNet Nbtstat | Microsoft. (n.d.). Nbtstat. Retrieved April 17, 2016. |
| TechNet Net Time | Microsoft. (n.d.). Net time. Retrieved November 25, 2016. |
| TechNet NetBIOS | Microsoft. (n.d.). NetBIOS Name Resolution. Retrieved November 17, 2017. |
| TechNet Netsh | Microsoft. (n.d.). Using Netsh. Retrieved February 13, 2017. |
| TechNet Netsh Firewall | Microsoft. (2009, June 3). Netsh Commands for Windows Firewall. Retrieved April 20, 2016. |
| TechNet Netstat | Microsoft. (n.d.). Netstat. Retrieved April 17, 2016. |
| TechNet O365 Outlook Rules | Koeller, B.. (2018, February 21). Defending Against Rules and Forms Injection. Retrieved November 5, 2019. |
| TechNet Ping | Microsoft. (n.d.). Ping. Retrieved April 8, 2016. |
| TechNet PowerShell | Microsoft. (n.d.). Windows PowerShell Scripting. Retrieved April 28, 2016. |
| TechNet RPC | Microsoft. (2003, March 28). What Is RPC?. Retrieved June 12, 2016. |
| TechNet Remote Desktop Services | Microsoft. (n.d.). Remote Desktop Services. Retrieved June 1, 2016. |
| TechNet Route | Microsoft. (n.d.). Route. Retrieved April 17, 2016. |
| TechNet Schtasks | Microsoft. (n.d.). Schtasks. Retrieved April 28, 2016. |
| TechNet Services | Microsoft. (n.d.). Services. Retrieved June 7, 2016. |
| TechNet Shared Folder | Microsoft. (n.d.). Share a Folder or Drive. Retrieved June 30, 2017. |
| TechNet Systeminfo | Microsoft. (n.d.). Systeminfo. Retrieved April 8, 2016. |
| TechNet Task Scheduler Security | Microsoft. (2005, January 21). Task Scheduler and security. Retrieved June 8, 2016. |
| Technet MS14-068 | Microsoft. (2014, November 18). Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780). Retrieved December 23, 2015. |
| Technet Net Use | Microsoft. (n.d.). Net Use. Retrieved November 25, 2016. |
| Technet Windows Time Service | Mathers, B. (2016, September 30). Windows Time Service Tools and Settings. Retrieved November 25, 2016. |
| Telefonica Snip3 December 2021 | Jornet, A. (2021, December 23). Snip3, an investigation into malware. Retrieved September 19, 2023. |
| Telephone Attack Delivery | Selena Larson, Sam Scholten, Timothy Kromphardt. (2021, November 4). Caught Beneath the Landline: A 411 on Telephone Oriented Attack Delivery. Retrieved January 5, 2022. |
| TempertonDarkHotel | Temperton, J. (2015, August 10). Hacking Team zero-day used in new Darkhotel attacks. Retrieved March 9, 2017. |
| Tetra Defense Sodinokibi March 2020 | Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024. |
| The BadPilot campaign | Microsoft Threat Intelligence. (2025, February 12). The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation. Retrieved June 18, 2025. |
| The DFIR Report AutoHotKey 2023 | The DFIR Report. (2023, February 6). Collect, Exfiltrate, Sleep, Repeat. Retrieved April 3, 2025. |
| The Hacker News | Ravie Lakshmanan. (2023, April 5). Hackers Using Self-Extracting Archives Exploit for Stealthy Backdoor Attacks. Retrieved March 3, 2025. |
| The Hacker News Lazarus Aug 2022 | Lakshmanan, R. (2022, August 17). North Korea Hackers Spotted Targeting Job Seekers with macOS Malware. Retrieved April 10, 2023. |
| The Hacker News PyPi Revival Hijack 2024 | Ravie Lakshmanan. (2024, September 4). Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival Hijack. Retrieved May 22, 2025. |
| The Remote Framebuffer Protocol | T. Richardson, J. Levine, RealVNC Ltd.. (2011, March). The Remote Framebuffer Protocol. Retrieved September 20, 2021. |
| TheEclecticLightCompany Quarantine and the flag | hoakley. (2020, October 29). Quarantine and the quarantine flag. Retrieved September 13, 2021. |
| TheEclecticLightCompany apple notarization | How Notarization Works. (2020, August 28). How notarization works. Retrieved September 13, 2021. |
| TheEvilBit DYLD_INSERT_LIBRARIES | Fitzl, C. (2019, July 9). DYLD_INSERT_LIBRARIES DYLIB injection in macOS / OSX. Retrieved March 26, 2020. |
| This is Security Command Line Confusion | B. Ancel. (2014, August 20). Poweliks – Command Line Confusion. Retrieved March 5, 2018. |
| Thornton tutorial VSCode shell September 2023 | Truvis Thornton. (2023, September 25). Visual Studio Code: embedded reverse shell and how to block, create Sentinel Detection, and add Environment Prevention. Retrieved March 24, 2025. |
| Threat Actor Targets the Manufacturing industry with Lumma Stealer and Amadey Bot | Cyble. (2024, December 5). Threat Actor Targets the Manufacturing industry with Lumma Stealer and Amadey Bot. Retrieved February 4, 2025. |
| Threat Matrix for Kubernetes | Weizman, Y. (2020, April 2). Threat Matrix for Kubernetes. Retrieved March 30, 2021. |
| ThreatConnect Anthem | ThreatConnect Research Team. (2015, February 27). The Anthem Hack: All Roads Lead to China. Retrieved January 26, 2016. |
| ThreatConnect Kimsuky September 2020 | ThreatConnect. (2020, September 28). Kimsuky Phishing Operations Putting In Work. Retrieved October 30, 2020. |
| ThreatExpert Agent.btz | Shevchenko, S.. (2008, November 30). Agent.btz - A Threat That Hit Pentagon. Retrieved April 8, 2016. |
| ThreatFabric_Crocodilus_June2025 | ThreatFabric. (2025, June 3). Crocodilus Mobile Malware: Evolving Fast, Going Global. Retrieved November 24, 2025. |
| ThreatFabric_Crocodilus_March2025 | ThreatFabric. (2025, March 28). Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices. Retrieved November 24, 2025. |
| ThreatGeek Derusbi Converge | Fidelis Threat Research Team. (2016, May 2). Turbo Twist: Two 64-bit Derusbi Strains Converge. Retrieved August 16, 2018. |
| ThreatPost Broadvoice Leak | Seals, T. (2020, October 15). Broadvoice Leak Exposes 350M Records, Personal Voicemail Transcripts. Retrieved October 20, 2020. |
| ThreatPost Social Media Phishing | O'Donnell, L. (2020, October 20). Facebook: A Top Launching Pad For Phishing Attacks. Retrieved October 20, 2020. |
| ThreatStream Evasion Analysis | Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.