Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| fsecure-netsky | F-Secure. (2004). Worm:W32/NetSky.H. Retrieved January 31, 2025. |
| fsutil_behavior | Microsoft. (2021, September 27). fsutil behavior. Retrieved January 14, 2022. |
| gbhackers Darkgate Malware 2024 | Divya. (2024, April 30). Darkgate Malware Leveraging Autohotkey Following Teams. Retrieved November 22, 2024. |
| gendigital | Threat Research Team. (2022, March 22). Operation Dragon Castling: APT group targeting betting companies. Retrieved September 25, 2025. |
| gist Arch package compromise 10JUL2018 | Catalin Cimpanu. (2018, July 10). ~x file downloaded in public Arch package compromise. Retrieved April 23, 2019. |
| group-ib_muddywater_infra | Rostovcev, N. (2023, April 18). SimpleHarm: Tracking MuddyWater’s infrastructure. Retrieved July 11, 2024. |
| group-ib_redcurl1 | Group-IB. (2020, August). RedCurl: The Pentest You Didn’t Know About. Retrieved August 9, 2024. |
| group-ib_redcurl2 | Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024. |
| groups man page | MacKenzie, D. and Youngman, J. (n.d.). groups(1) - Linux man page. Retrieved January 11, 2024. |
| haking9 libpcap network sniffing | Luis Martin Garcia. (2008, February 1). Hakin9 Issue 2/2008 Vol 3 No.2 VoIP Abuse: Storming SIP Security. Retrieved October 18, 2022. |
| hasherezade debug | hasherezade. (2021, June 30). Module 3 - Understanding and countering malware's evasion and self-defence. Retrieved April 1, 2022. |
| hexacorn | hexacorn. (2015, January 13). Beyond good ol’ Run key, Part 24. Retrieved September 25, 2025. |
| hexed osx.dok analysis 2019 | fluffybunny. (2019, July 9). OSX.Dok Analysis. Retrieved November 17, 2024. |
| hhs-email-bombing | U.S. Department of Health and Human Services. (2024, March 12). Defense and Mitigations from E-mail Bombing. Retrieved January 31, 2025. |
| how_pwd_rev_enc_1 | Teusink, N. (2009, August 25). Passwords stored using reversible encryption: how it works (part 1). Retrieved November 17, 2021. |
| how_pwd_rev_enc_2 | Teusink, N. (2009, August 26). Passwords stored using reversible encryption: how it works (part 2). Retrieved November 17, 2021. |
| httrack_unhcr | RISKIQ. (2022, March 15). RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure. Retrieved July 29, 2022. |
| iDefense Rootkit Overview | Chuvakin, A. (2003, February). An Overview of Rootkits. Retrieved September 12, 2024. |
| iOS URL Scheme | Ostorlab. (n.d.). iOS URL Scheme Hijacking. Retrieved February 9, 2024. |
| iPhone Charging Cable Hack | Zack Whittaker. (2019, August 12). This hacker’s iPhone charging cable can hijack your computer. Retrieved May 25, 2022. |
| iSIGHT Sandworm 2014 | Hultquist, J.. (2016, January 7). Sandworm Team and the Ukrainian Power Authority Attacks. Retrieved October 6, 2017. |
| iSight Sandworm Oct 2014 | Ward, S.. (2014, October 14). iSIGHT discovers zero-day vulnerability CVE-2014-4114 used in Russian cyber-espionage campaign. Retrieved November 17, 2024. |
| ic3-dprk | FBI, State Department, NSA. (2024, May 2). North Korean Actors Exploit Weak DMARC Security Policies to Mask Spearphishing Efforts. Retrieved April 2, 2025. |
| id man page | MacKenzie, D. and Robbins, A. (n.d.). id(1) - Linux man page. Retrieved January 11, 2024. |
| insecure_reg_perms | Clément Labro. (2020, November 12). Windows RpcEptMapper Service Insecure Registry Permissions EoP. Retrieved August 25, 2021. |
| intezer stripped binaries elf files 2018 | Ignacio Sanmillan. (2018, February 7). Executable and Linkable Format 101. Part 2: Symbols. Retrieved September 29, 2022. |
| intezer-kaiji-malware | Paul Litvak. (2020, May 4). Kaiji: New Chinese Linux malware turning to Golang. Retrieved December 17, 2020. |
| ired Dumping LSA Secrets | Mantvydas Baranauskas. (2019, November 16). Dumping LSA Secrets. Retrieved February 21, 2020. |
| ired mscache | Mantvydas Baranauskas. (2019, November 16). Dumping and Cracking mscash - Cached Domain Credentials. Retrieved February 21, 2020. |
| ise Password Manager February 2019 | ise. (2019, February 19). Password Managers: Under the Hood of Secrets Management. Retrieved January 22, 2021. |
| jRAT Symantec Aug 2018 | Sharma, R. (2018, August 15). Revamped jRAT Uses New Anti-Parsing Techniques. Retrieved September 21, 2018. |
| krebs-email-bombing | Brian Krebs. (2016, August 18). Massive Email Bombs Target .Gov Addresses. Retrieved January 31, 2025. |
| kroll bpl | Dave Truman. (2024, June 24). Novel Technique Combination Used In IDATLOADER Distribution. Retrieved January 30, 2025. |
| lambert systemd 2022 | Tony Lambert. (2022, November 13). ATT&CK T1501: Understanding systemd service persistence. Retrieved March 20, 2023. |
| launchd Keywords for plists | Dennis German. (2020, November 20). launchd Keywords for plists. Retrieved October 7, 2021. |
| lazgroup_idn_phishing | RISKIQ. (2017, December 20). Mining Insights: Infrastructure Analysis of Lazarus Group Cyber Attacks on the Cryptocurrency Industry. Retrieved July 29, 2022. |
| libzip | D. Baron, T. Klausner. (2020). libzip. Retrieved February 20, 2020. |
| linux system time | ArchLinux. (2024, February 1). System Time. Retrieved March 27, 2024. |
| lolbas project Ieframe.dll | lolbas project. (n.d.). Ieframe.dll. Retrieved October 5, 2025. |
| lolbas project Zipfldr.dll | lolbas project. (n.d.). Zipfldr.dll. Retrieved October 5, 2025. |
| lsmod man | Kerrisk, M. (2022, December 18). lsmod(8) — Linux manual page. Retrieved March 28, 2023. |
| lucr-3: Getting SaaS-y in the cloud | Ian Ahl. (2023, September 20). LUCR-3: Scattered Spider Getting SaaS-y In The Cloud. Retrieved September 20, 2023. |
| mDNS RFC | S. Cheshire, M. Krochmal. (2013, February). Multicast DNS. Retrieved February 2, 2026. |
| macOS APT Activity Bradley | Jaron Bradley. (2021, November 14). What does APT Activity Look Like on macOS?. Retrieved January 19, 2022. |
| macOS Foundation | Apple. (n.d.). Foundation. Retrieved July 1, 2020. |
| macOS Hierarchical File System Overview | Tenon. (n.d.). Retrieved October 12, 2021. |
| macOS MS office sandbox escape | Cedric Owens. (2021, May 22). macOS MS Office Sandbox Brain Dump. Retrieved August 20, 2021. |
| macOS root VNC login without authentication | Nick Miles. (2017, November 30). Detecting macOS High Sierra root account without authentication. Retrieved September 20, 2021. |
| magnusviri emond Apr 2016 | Reynolds, James. (2016, April 7). What is emond?. Retrieved September 10, 2019. |
| mailx man page | Michael Kerrisk. (2021, August 27). mailx(1p) — Linux manual page. Retrieved June 10, 2022. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.