Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| malware_hides_service | Lawrence Abrams. (2004, September 10). How Malware hides and is installed as a Service. Retrieved August 30, 2021. |
| mandiant-masking | Simonian, Nick. (2023, May 22). Don't @ Me: URL Obfuscation Through Schema Abuse. Retrieved January 17, 2024. |
| mandiant_apt44_unearthing_sandworm | Roncone, G. et al. (n.d.). APT44: Unearthing Sandworm. Retrieved July 11, 2024. |
| mbed-crypto | ARMmbed. (2018, June 21). Mbed Crypto. Retrieved February 15, 2021. |
| medium evil twin | Gihan, Kavishka. (2021, August 8). Wireless Security— Evil Twin Attack. Retrieved September 17, 2024. |
| microsoft remote preloading | Microsoft. (2014, May 13). Microsoft Security Advisory 2269637: Insecure Library Loading Could Allow Remote Code Execution. Retrieved January 30, 2025. |
| microsoft_services_registry_tree | Microsoft. (2021, August 5). HKLM\SYSTEM\CurrentControlSet\Services Registry Tree. Retrieved August 25, 2021. |
| mining_ruby_reversinglabs | Maljic, T. (2020, April 16). Mining for malicious Ruby gems. Retrieved October 15, 2022. |
| mitm_tls_downgrade_att | praetorian Editorial Team. (2014, August 19). Man-in-the-Middle TLS Protocol Downgrade Attack. Retrieved December 8, 2021. |
| mmc_vulns | Boxiner, A., Vaknin, E. (2019, June 11). Microsoft Management Console (MMC) Vulnerabilities. Retrieved September 24, 2021. |
| mod_rewrite | Bluescreenofjeff.com. (2015, April 12). Combatting Incident Responders with Apache mod_rewrite. Retrieved February 13, 2024. |
| modinfo man | Russell, R. (n.d.). modinfo(8) - Linux man page. Retrieved March 28, 2023. |
| mozilla_sec_adv_2012 | Robert Kugler. (2012, November 20). Mozilla Foundation Security Advisory 2012-98. Retrieved March 10, 2017. |
| nccgroup Smuggling HTA 2017 | Warren, R. (2017, August 8). Smuggling HTA files in Internet Explorer/Edge. Retrieved September 12, 2024. |
| netlab360 rotajakiro vs oceanlotus | Alex Turing. (2021, May 6). RotaJakiro, the Linux version of the OceanLotus. Retrieved June 14, 2023. |
| new_rogue_DHCP_serv_malware | Irwin, Ullrich, J. (2009, March 16). new rogue-DHCP server malware. Retrieved January 14, 2022. |
| new_rust_based_ransomware | Symantec Threat Hunter Team. (2021, December 16). Noberus: Technical Analysis Shows Sophistication of New Rust-based Ransomware. Retrieved January 14, 2022. |
| nixCraft - John the Ripper | Vivek Gite. (2014, September 17). Linux Password Cracking: Explain unshadow and john Commands (John the Ripper Tool). Retrieved February 19, 2020. |
| nixCraft macOS PATH variables | Vivek Gite. (2023, August 22). MacOS – Set / Change $PATH Variable Command. Retrieved September 28, 2023. |
| nohup Linux Man | Meyering, J. (n.d.). nohup(1). Retrieved August 30, 2023. |
| objective-see 2017 review | Patrick Wardle. (n.d.). Retrieved March 20, 2018. |
| objective-see ay mami 2018 | Patrick Wardle. (2018, January 11). Ay MaMi. Retrieved March 19, 2018. |
| objective-see windtail1 dec 2018 | Wardle, Patrick. (2018, December 20). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 1). Retrieved October 3, 2019. |
| objective-see windtail2 jan 2019 | Wardle, Patrick. (2019, January 15). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2). Retrieved October 3, 2019. |
| objectivesee osx.shlayer apple approved 2020 | Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021. |
| objsee mac malware 2017 | Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018. |
| objsee netwire backdoor 2019 | Patrick Wardle. (2019, June 20). Burned by Fire(fox). Retrieved October 1, 2021. |
| okta | okta. (n.d.). What Happens If Your JWT Is Stolen?. Retrieved September 12, 2019. |
| on security kerberos linux | Boal, Calum. (2020, January 28). Abusing Kerberos From Linux - An Overview of Available Tools. Retrieved September 17, 2024. |
| paloalto Tropic Trooper 2016 | Ray, V., et al. (2016, November 22). Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy. Retrieved December 18, 2020. |
| passcape Windows Vault | Passcape. (n.d.). Windows Password Recovery - Vault Explorer and Decoder. Retrieved November 24, 2020. |
| pcodedmp Bontchev | Bontchev, V. (2019, July 30). pcodedmp.py - A VBA p-code disassembler. Retrieved September 17, 2020. |
| phishing-krebs | Brian Krebs. (2024, March 28). Thread Hijacking: Phishes That Prey on Your Curiosity. Retrieved September 27, 2024. |
| phobos_virustotal | Phobos Ransomware. (2020, December 30). Phobos Ransomware, Fast.exe. Retrieved September 20, 2021. |
| polygot_icedID | Lim, M. (2022, September 27). More Than Meets the Eye: Exposing a Polyglot File That Delivers IcedID. Retrieved September 29, 2022. |
| polymorphic-blackberry | Blackberry. (n.d.). What is Polymorphic Malware?. Retrieved September 27, 2024. |
| polymorphic-linkedin | Sherwin Akshay. (2024, May 28). Techniques for concealing malware and hindering analysis: Packing up and unpacking stuff. Retrieved September 27, 2024. |
| polymorphic-medium | Shellseekercyber. (2024, January 7). Explainer: Packed Malware. Retrieved September 27, 2024. |
| polymorphic-sentinelone | SentinelOne. (2023, March 18). What is Polymorphic Malware? Examples and Challenges. Retrieved September 27, 2024. |
| proofpoint-selfpwn | Tommy Madjar, Dusty Miller, Selena Larson. (2024, June 17). From Clipboard to Compromise: A PowerShell Self-Pwn. Retrieved August 2, 2024. |
| pubprn | Jason Gerend. (2017, October 16). pubprn. Retrieved July 23, 2021. |
| push notification -mcafee | Craig Schmugar. (2021, May 17). Scammers Impersonating Windows Defender to Push Malicious Windows Apps. Retrieved March 14, 2025. |
| push notifications - malwarebytes | Pieter Arntz. (2019, January 22). Browser push notifications: a feature asking to be abused. Retrieved March 14, 2025. |
| qr-phish-agriculture | Tim Bedard and Tyler Johnson. (2023, October 4). QR Code Scams & Phishing. Retrieved November 27, 2023. |
| rapid7-email-bombing | Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025. |
| reed thiefquest ransomware analysis | Thomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 22, 2021. |
| rfc2131 | Droms, R. (1997, March). Dynamic Host Configuration Protocol. Retrieved March 9, 2022. |
| rfc3315 | J. Bound, et al. (2003, July). Dynamic Host Configuration Protocol for IPv6 (DHCPv6). Retrieved June 27, 2022. |
| rundll32.exe defense evasion | Ariel silver. (2022, February 1). Defense Evasion Techniques. Retrieved April 8, 2022. |
| ryhanson phishery SEPT 2016 | Hanson, R. (2016, September 24). phishery. Retrieved July 21, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.