ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Wikipedia Character EncodingWikipedia. (2017, February 19). Character Encoding. Retrieved March 1, 2017.
Wikipedia Code SigningWikipedia. (2015, November 10). Code Signing. Retrieved March 31, 2016.
Wikipedia DuquWikipedia. (2017, December 29). Duqu. Retrieved April 10, 2018.
Wikipedia HTML ApplicationWikipedia. (2017, October 14). HTML Application. Retrieved October 27, 2017.
Wikipedia IfconfigWikipedia. (2016, January 26). ifconfig. Retrieved April 17, 2016.
Wikipedia LLMNRWikipedia. (2016, July 7). Link-Local Multicast Name Resolution. Retrieved November 17, 2017.
Wikipedia Man in the BrowserWikipedia. (2017, October 28). Man-in-the-browser. Retrieved January 10, 2018.
Wikipedia OSIWikipedia. (n.d.). List of network protocols (OSI model). Retrieved December 4, 2014.
Wikipedia Password crackingWikipedia. (n.d.). Password cracking. Retrieved December 23, 2015.
Wikipedia Public Key CryptoWikipedia. (2017, June 29). Public-key cryptography. Retrieved July 5, 2017.
Wikipedia Root CertificateWikipedia. (2016, December 6). Root certificate. Retrieved February 20, 2017.
Wikipedia RootkitWikipedia. (2016, June 1). Rootkit. Retrieved June 2, 2016.
Wikipedia ScreensaverWikipedia. (2017, November 22). Screensaver. Retrieved December 5, 2017.
Wikipedia Server Message BlockWikipedia. (2017, December 16). Server Message Block. Retrieved December 21, 2017.
Wikipedia Shared ResourceWikipedia. (2017, April 15). Shared resource. Retrieved June 30, 2017.
Wikipedia UEFIWikipedia. (2017, July 10). Unified Extensible Firmware Interface. Retrieved July 11, 2017.
Wikipedia VBAWikipedia. (n.d.). Visual Basic for Applications. Retrieved August 13, 2020.
Wikipedia Windows RegistryWikipedia. (n.d.). Windows Registry. Retrieved February 2, 2015.
Wikipedia pwdumpWikipedia. (2007, August 9). pwdump. Retrieved June 22, 2016.
William Largent June 2018William Largent 2018, June 06 VPNFilter Update - VPNFilter exploits endpoints, targets new devices Retrieved. 2019/03/28
WinOSBite verclsid.exeverclsid-exe. (2019, December 17). verclsid.exe File Information - What is it & How to Block . Retrieved November 17, 2024.
WinRAR HomepageA. Roshal. (2020). RARLAB. Retrieved February 20, 2020.
WinZip HomepageCorel Corporation. (2020). WinZip. Retrieved February 20, 2020.
Windows AppleJeus GReATGlobal Research & Analysis Team, Kaspersky Lab (GReAT). (2018, August 23). Operation AppleJeus: Lazarus hits cryptocurrency exchange with fake installer and macOS malware. Retrieved September 27, 2022.
Windows Commands JPCERTTomonaga, S. (2016, January 26). Windows Commands Abused by Attackers. Retrieved February 2, 2016.
Windows Malware Infecting AndroidLucian Constantin. (2014, January 23). Windows malware tries to infect Android devices connected to PCs. Retrieved May 25, 2022.
Windows NT Command ShellTim Hill. (2014, February 2). The Windows NT Command Shell. Retrieved December 5, 2014.
Windows OS Hub RDPWindows OS Hub. (2021, November 10). How to Allow Multiple RDP Sessions in Windows 10 and 11?. Retrieved March 28, 2022.
Windows Privilege Escalation Guideabsolomb. (2018, January 26). Windows Privilege Escalation Guide. Retrieved August 10, 2018.
Windows Process Injection KernelCallbackTableodzhan. (2019, May 25). Windows Process Injection: KernelCallbackTable used by FinFisher / FinSpy. Retrieved February 4, 2022.
Windows Server Containers Are OpenDaniel Prizmant. (2020, July 15). Windows Server Containers Are Open, and Here's How You Can Break Out. Retrieved October 1, 2021.
Windows Unquoted ServicesHackHappy. (2018, April 23). Windows Privilege Escalation – Unquoted Services. Retrieved August 10, 2018.
WindowsIR Anti-Forensic TechniquesCarvey, H. (2013, July 23). HowTo: Determine/Detect the use of Anti-Forensics Techniques. Retrieved June 3, 2016.
Wine API samlib.dllWine API. (n.d.). samlib.dll. Retrieved November 17, 2024.
Winexe Github Sept 2013Skalkotos, N. (2013, September 20). WinExe. Retrieved January 22, 2018.
WireLurkerClaud Xiao. (n.d.). WireLurker: A New Era in iOS and OS X Malware. Retrieved July 10, 2017.
Wired Lockergoga 2019Greenberg, A. (2019, March 25). A Guide to LockerGoga, the Ransomware Crippling Industrial Firms. Retrieved July 17, 2019.
Wired Magecart S3 Buckets, 2019Barrett, B.. (2019, July 11). Hack Brief: A Card-Skimming Hacker Group Hit 17K Domains—and Counting. Retrieved October 4, 2019.
Wired Russia CyberwarGreenberg, A. (2022, November 10). Russia’s New Cyberwarfare in Ukraine Is Fast, Dirty, and Relentless. Retrieved March 22, 2023.
Wired SandCat Oct 2019Zetter, K. (2019, October 3). Researchers Say They Uncovered Uzbekistan Hacking Operations Due to Spectacularly Bad OPSEC. Retrieved October 15, 2020.
Wired Uber BreachAndy Greenberg. (2017, January 21). Hack Brief: Uber Paid Off Hackers to Hide a 57-Million User Data Breach. Retrieved May 14, 2021.
WithSecure Kapeka 2024Mohammad Kazem Hassan Nejad, WithSecure. (2024, April 17). KAPEKA A novel backdoor spotted in Eastern Europe. Retrieved January 6, 2025.
WithSecure Lazarus-NoPineapple Threat Intel Report 2023Ruohonen, S. & Robinson, S. (2023, February 2). No Pineapple! -DPRK Targeting of Medical Research and Technology Sector. Retrieved July 10, 2023.
Wits End and Shady PowerShell ProfilesDeRyke, A.. (2019, June 7). Lab Notes: Persistence and Privilege Elevation using the Powershell Profile. Retrieved July 8, 2019.
Wiz Midnight Blizzard 2024Lior Sonntag. (2024, February 8). Midnight Blizzard attack on Microsoft corporate environment: a detailed analysis, detections and recommendations. Retrieved March 20, 2025.
Wiz Mini Shai-Hulud MAY 2026McCarthy, R., Cohen, A., and Read, B. (2026, May 12). Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised. Retrieved July 16, 2026.
Wiz Shai-Hulud September 2025Merav Bar, Rami McCarthy, Barak Sharoni. (2025, September 16). Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware. Retrieved April 9, 2026.
Wiz TeamPCP KICS MAR 2026McCarthy, R., Haughom, J., Read, B. (2026, March 23). KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack. Retrieved July 1, 2026.
Wiz TeamPCP Profile MAY 2026Wiz. (2026, May 20). TeamPCP. Retrieved July 16, 2026.
Wiz Trivy Compromise MAR 2026McCarthy, R. (2026, March 20). Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack. Retrieved July 1, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.