ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
archlinux Systemd Timers Aug 2020archlinux. (2020, August 11). systemd/Timers. Retrieved October 12, 2020.
atomic-red proc file systemAtomic Red Team. (2023, November). T1003.007 - OS Credential Dumping: Proc Filesystem. Retrieved March 28, 2024.
att_def_ps_loggingHao, M. (2019, February 27). Attack and Defense Around PowerShell Event Logging. Retrieved November 24, 2021.
auditpol.exe_STRONTICSTRONTIC. (n.d.). auditpol.exe. Retrieved September 9, 2021.
azure az diskAzure. (n.d.). az disk. Retrieved October 20, 2025.
bad_luck_blackcatKaspersky Global Research & Analysis Team (GReAT). (2022). A Bad Luck BlackCat. Retrieved May 5, 2022.
baeldung Linux proc map 2022baeldung. (2022, April 8). Understanding the Linux /proc/id/maps File. Retrieved March 31, 2023.
bencane blog bashrcBenjamin Cane. (2013, September 16). Understanding a little more about /etc/profile and /etc/bashrc. Retrieved September 25, 2024.
blackmatter_blackcatPereira, T. Huey, C. (2022, March 17). From BlackMatter to BlackCat: Analyzing two attacks from one affiliate. Retrieved May 5, 2022.
bypass_webproxy_filteringFehrman, B. (2017, April 13). How to Bypass Web-Proxy Filtering. Retrieved September 20, 2019.
byt3bl33d3r NTLM RelayingSalvati, M. (2017, June 2). Practical guide to NTLM Relaying in 2017 (A.K.A getting a foothold in under 5 minutes). Retrieved February 7, 2019.
capture_embedded_packet_on_softwareCisco. (2022, August 17). Configure and Capture Embedded Packet on Software. Retrieved July 13, 2022.
change_rdp_port_contiThe DFIR Report. (2022, March 1). "Change RDP port" #ContiLeaks. Retrieved September 12, 2024.
cipher.exeMicrosoft Support. (n.d.). Cipher.exe Security Tool for the Encrypting File System. Retrieved February 25, 2025.
cisa_malware_orgs_ukraineCISA. (2022, April 28). Alert (AA22-057A) Update: Destructive Malware Targeting Organizations in Ukraine. Retrieved July 29, 2022.
cisco_deploy_rsa_keysCisco. (2023, February 17). Chapter: Deploying RSA Keys Within a PKI . Retrieved March 27, 2023.
cisco_ip_ssh_pubkey_ch_cmdCisco. (2021, August 23). ip ssh pubkey-chain. Retrieved July 13, 2022.
cisco_username_cmdCisco. (2023, March 6). username - Cisco IOS Security Command Reference: Commands S to Z. Retrieved July 13, 2022.
clip_win_serverMicrosoft, JasonGerend, et al. (2023, February 3). clip. Retrieved June 21, 2022.
cobaltstrike manualStrategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.
code_persistence_zshLeo Pitt. (2020, November 11). Github - PersistentJXA/BashProfilePersist.js. Retrieved January 11, 2021.
copy_cmd_ciscoCisco. (2022, August 16). copy - Cisco IOS Configuration Fundamentals Command Reference . Retrieved July 13, 2022.
creatingXPCservicesApple. (2016, September 9). Creating XPC Services. Retrieved April 19, 2022.
cybereason osx protonAmit Serper. (2018, May 10). ProtonB What this Mac Malware Actually Does. Retrieved March 19, 2018.
cyberproof-double-bounceItkin, Liora. (2022, September 1). Double-bounced attacks with email spoofing . Retrieved February 24, 2023.
dhs_threat_to_net_devicesU.S. Department of Homeland Security. (2016, August 30). The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations. Retrieved July 29, 2022.
diantz.exe_lolbasLiving Off The Land Binaries, Scripts and Libraries (LOLBAS). (n.d.). Diantz.exe. Retrieved October 25, 2021.
disable_notif_synology_ransomTheDFIRReport. (2022, March 1). Disabling notifications on Synology servers before ransom. Retrieved September 12, 2024.
disable_win_evt_loggingHeiligenstein, L. (n.d.). REP-25: Disable Windows Event Logging. Retrieved April 7, 2022.
dll pre load owaspOWASP. (n.d.). Binary Planting. Retrieved January 30, 2025.
dns_changer_trojansAbendan, O. (2012, June 14). How DNS Changer Trojans Direct Users to Threats. Retrieved October 28, 2021.
dtex DPRK 2025 structure ITworkersMichael “Barni” Barnhart, DTEX, and Anonymous SMEs. (2025, May 14). Exposing DPRK's Cyber Syndicate and Hidden IT Workforce. Retrieved September 3, 2025.
dump_pwd_dcsyncMetcalf, S. (2015, November 22). Dump Clear-Text Passwords for All Admins in the Domain Using Mimikatz DCSync. Retrieved November 15, 2021.
eSentire FIN7 July 2021eSentire. (2021, July 21). Notorious Cybercrime Gang, FIN7, Lands Malware in Law Firm Using Fake Legal Complaint Against Jack Daniels’ Owner, Brown-Forman Inc.. Retrieved September 20, 2021.
emotet_hc3_nov2023Office of Information Security, Health Sector Cybersecurity Coordination Center. (2023, November 16). Emotet Malware: The Enduring and Persistent Threat to the Health Sector. Retrieved June 19, 2024.
emotet_trendmicro_mar2023Kenefick, I. (2023, March 13). Emotet Returns, Now Adopts Binary Padding for Evasion. Retrieved June 19, 2024.
engima0x3 DNX BypassNelson, M. (2017, November 17). Bypassing Application Whitelisting By Using dnx.exe. Retrieved May 25, 2017.
engima0x3 RCSI BypassNelson, M. (2016, November 21). Bypassing Application Whitelisting By Using rcsi.exe. Retrieved May 26, 2017.
enigma0x3 Fileless UAC BypassNelson, M. (2016, August 15). "Fileless" UAC Bypass using eventvwr.exe and Registry Hijacking. Retrieved December 27, 2016.
enigma0x3 normal.dotmNelson, M. (2014, January 23). Maintaining Access with normal.dotm. Retrieved July 3, 2017.
erase_cmd_ciscoCisco. (2022, August 16). erase - Cisco IOS Configuration Fundamentals Command Reference . Retrieved July 13, 2022.
eset_osx_flashbackESET. (2012, January 1). OSX/Flashback. Retrieved April 19, 2022.
evolution of pirpiYates, M. (2017, June 18). APT3 Uncovered: The code evolution of Pirpi. Retrieved September 28, 2017.
exatrack bpf filters passive backdoorsExaTrack. (2022, May 11). Tricephalic Hellkeeper: a tale of a passive backdoor. Retrieved October 18, 2022.
f-secure janicabBrod. (2013, July 15). Signed Mac Malware Using Right-to-Left Override Trick. Retrieved July 17, 2017.
falconoverwatch_blackcat_attackFalcon OverWatch Team. (2022, March 23). Falcon OverWatch Threat Hunting Contributes to Seamless Protection Against Novel BlackCat Attack. Retrieved May 5, 2022.
fileinfo plist file descriptionFileInfo.com team. (2019, November 26). .PLIST File Extension. Retrieved October 12, 2021.
format_cmd_ciscoCisco. (2022, August 16). format - Cisco IOS Configuration Fundamentals Command Reference. Retrieved July 13, 2022.
freedesktop systemd.serviceFree Desktop. (n.d.). systemd.service — Service unit configuration. Retrieved March 20, 2023.
fsecure NanHaiShu July 2016F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.