Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| archlinux Systemd Timers Aug 2020 | archlinux. (2020, August 11). systemd/Timers. Retrieved October 12, 2020. |
| atomic-red proc file system | Atomic Red Team. (2023, November). T1003.007 - OS Credential Dumping: Proc Filesystem. Retrieved March 28, 2024. |
| att_def_ps_logging | Hao, M. (2019, February 27). Attack and Defense Around PowerShell Event Logging. Retrieved November 24, 2021. |
| auditpol.exe_STRONTIC | STRONTIC. (n.d.). auditpol.exe. Retrieved September 9, 2021. |
| azure az disk | Azure. (n.d.). az disk. Retrieved October 20, 2025. |
| bad_luck_blackcat | Kaspersky Global Research & Analysis Team (GReAT). (2022). A Bad Luck BlackCat. Retrieved May 5, 2022. |
| baeldung Linux proc map 2022 | baeldung. (2022, April 8). Understanding the Linux /proc/id/maps File. Retrieved March 31, 2023. |
| bencane blog bashrc | Benjamin Cane. (2013, September 16). Understanding a little more about /etc/profile and /etc/bashrc. Retrieved September 25, 2024. |
| blackmatter_blackcat | Pereira, T. Huey, C. (2022, March 17). From BlackMatter to BlackCat: Analyzing two attacks from one affiliate. Retrieved May 5, 2022. |
| bypass_webproxy_filtering | Fehrman, B. (2017, April 13). How to Bypass Web-Proxy Filtering. Retrieved September 20, 2019. |
| byt3bl33d3r NTLM Relaying | Salvati, M. (2017, June 2). Practical guide to NTLM Relaying in 2017 (A.K.A getting a foothold in under 5 minutes). Retrieved February 7, 2019. |
| capture_embedded_packet_on_software | Cisco. (2022, August 17). Configure and Capture Embedded Packet on Software. Retrieved July 13, 2022. |
| change_rdp_port_conti | The DFIR Report. (2022, March 1). "Change RDP port" #ContiLeaks. Retrieved September 12, 2024. |
| cipher.exe | Microsoft Support. (n.d.). Cipher.exe Security Tool for the Encrypting File System. Retrieved February 25, 2025. |
| cisa_malware_orgs_ukraine | CISA. (2022, April 28). Alert (AA22-057A) Update: Destructive Malware Targeting Organizations in Ukraine. Retrieved July 29, 2022. |
| cisco_deploy_rsa_keys | Cisco. (2023, February 17). Chapter: Deploying RSA Keys Within a PKI . Retrieved March 27, 2023. |
| cisco_ip_ssh_pubkey_ch_cmd | Cisco. (2021, August 23). ip ssh pubkey-chain. Retrieved July 13, 2022. |
| cisco_username_cmd | Cisco. (2023, March 6). username - Cisco IOS Security Command Reference: Commands S to Z. Retrieved July 13, 2022. |
| clip_win_server | Microsoft, JasonGerend, et al. (2023, February 3). clip. Retrieved June 21, 2022. |
| cobaltstrike manual | Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017. |
| code_persistence_zsh | Leo Pitt. (2020, November 11). Github - PersistentJXA/BashProfilePersist.js. Retrieved January 11, 2021. |
| copy_cmd_cisco | Cisco. (2022, August 16). copy - Cisco IOS Configuration Fundamentals Command Reference . Retrieved July 13, 2022. |
| creatingXPCservices | Apple. (2016, September 9). Creating XPC Services. Retrieved April 19, 2022. |
| cybereason osx proton | Amit Serper. (2018, May 10). ProtonB What this Mac Malware Actually Does. Retrieved March 19, 2018. |
| cyberproof-double-bounce | Itkin, Liora. (2022, September 1). Double-bounced attacks with email spoofing . Retrieved February 24, 2023. |
| dhs_threat_to_net_devices | U.S. Department of Homeland Security. (2016, August 30). The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations. Retrieved July 29, 2022. |
| diantz.exe_lolbas | Living Off The Land Binaries, Scripts and Libraries (LOLBAS). (n.d.). Diantz.exe. Retrieved October 25, 2021. |
| disable_notif_synology_ransom | TheDFIRReport. (2022, March 1). Disabling notifications on Synology servers before ransom. Retrieved September 12, 2024. |
| disable_win_evt_logging | Heiligenstein, L. (n.d.). REP-25: Disable Windows Event Logging. Retrieved April 7, 2022. |
| dll pre load owasp | OWASP. (n.d.). Binary Planting. Retrieved January 30, 2025. |
| dns_changer_trojans | Abendan, O. (2012, June 14). How DNS Changer Trojans Direct Users to Threats. Retrieved October 28, 2021. |
| dtex DPRK 2025 structure ITworkers | Michael “Barni” Barnhart, DTEX, and Anonymous SMEs. (2025, May 14). Exposing DPRK's Cyber Syndicate and Hidden IT Workforce. Retrieved September 3, 2025. |
| dump_pwd_dcsync | Metcalf, S. (2015, November 22). Dump Clear-Text Passwords for All Admins in the Domain Using Mimikatz DCSync. Retrieved November 15, 2021. |
| eSentire FIN7 July 2021 | eSentire. (2021, July 21). Notorious Cybercrime Gang, FIN7, Lands Malware in Law Firm Using Fake Legal Complaint Against Jack Daniels’ Owner, Brown-Forman Inc.. Retrieved September 20, 2021. |
| emotet_hc3_nov2023 | Office of Information Security, Health Sector Cybersecurity Coordination Center. (2023, November 16). Emotet Malware: The Enduring and Persistent Threat to the Health Sector. Retrieved June 19, 2024. |
| emotet_trendmicro_mar2023 | Kenefick, I. (2023, March 13). Emotet Returns, Now Adopts Binary Padding for Evasion. Retrieved June 19, 2024. |
| engima0x3 DNX Bypass | Nelson, M. (2017, November 17). Bypassing Application Whitelisting By Using dnx.exe. Retrieved May 25, 2017. |
| engima0x3 RCSI Bypass | Nelson, M. (2016, November 21). Bypassing Application Whitelisting By Using rcsi.exe. Retrieved May 26, 2017. |
| enigma0x3 Fileless UAC Bypass | Nelson, M. (2016, August 15). "Fileless" UAC Bypass using eventvwr.exe and Registry Hijacking. Retrieved December 27, 2016. |
| enigma0x3 normal.dotm | Nelson, M. (2014, January 23). Maintaining Access with normal.dotm. Retrieved July 3, 2017. |
| erase_cmd_cisco | Cisco. (2022, August 16). erase - Cisco IOS Configuration Fundamentals Command Reference . Retrieved July 13, 2022. |
| eset_osx_flashback | ESET. (2012, January 1). OSX/Flashback. Retrieved April 19, 2022. |
| evolution of pirpi | Yates, M. (2017, June 18). APT3 Uncovered: The code evolution of Pirpi. Retrieved September 28, 2017. |
| exatrack bpf filters passive backdoors | ExaTrack. (2022, May 11). Tricephalic Hellkeeper: a tale of a passive backdoor. Retrieved October 18, 2022. |
| f-secure janicab | Brod. (2013, July 15). Signed Mac Malware Using Right-to-Left Override Trick. Retrieved July 17, 2017. |
| falconoverwatch_blackcat_attack | Falcon OverWatch Team. (2022, March 23). Falcon OverWatch Threat Hunting Contributes to Seamless Protection Against Novel BlackCat Attack. Retrieved May 5, 2022. |
| fileinfo plist file description | FileInfo.com team. (2019, November 26). .PLIST File Extension. Retrieved October 12, 2021. |
| format_cmd_cisco | Cisco. (2022, August 16). format - Cisco IOS Configuration Fundamentals Command Reference. Retrieved July 13, 2022. |
| freedesktop systemd.service | Free Desktop. (n.d.). systemd.service — Service unit configuration. Retrieved March 20, 2023. |
| fsecure NanHaiShu July 2016 | F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.