Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Free Desktop Application Autostart Feb 2006 | Free Desktop. (2006, February 13). Desktop Application Autostart Specification. Retrieved September 12, 2019. |
| Free Desktop Entry Keys | Free Desktop. (2017, December 24). Recognized Desktop Entry Keys. Retrieved November 17, 2024. |
| Free Trial PurpleUrchin | Gamazo, William. Quist, Nathaniel.. (2023, January 5). PurpleUrchin Bypasses CAPTCHA and Steals Cloud Platform Resources. Retrieved February 28, 2024. |
| FreeDesktop Journal | freedesktop.org. (n.d.). systemd-journald.service. Retrieved June 15, 2022. |
| Freejacked | Clark, Michael. (2023, August 14). Google’s Vertex AI Platform Gets Freejacked. Retrieved February 28, 2024. |
| Frisk DMA August 2016 | Ulf Frisk. (2016, August 5). Direct Memory Attack the Kernel. Retrieved March 30, 2018. |
| Fysbis Dr Web Analysis | Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017. |
| Fysbis Palo Alto Analysis | Bryan Lee and Rob Downs. (2016, February 12). A Look Into Fysbis: Sofacy’s Linux Backdoor. Retrieved September 10, 2017. |
| G Data Sodinokibi June 2019 | Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020. |
| GCN RSA June 2011 | Jackson, William. (2011, June 7). RSA confirms its tokens used in Lockheed hack. Retrieved November 17, 2024. |
| GCP Create Cloud Identity Users | Google. (n.d.). Create Cloud Identity user accounts. Retrieved January 29, 2020. |
| GCP IAM Conditions | Google Cloud. (n.d.). Overview of IAM Conditions. Retrieved January 2, 2024. |
| GCP Packet Mirroring | Google Cloud. (n.d.). Packet Mirroring overview. Retrieved March 17, 2022. |
| GCP SSH Key Add | Google. (n.d.). gcloud compute os-login ssh-keys add. Retrieved October 1, 2020. |
| GCP Service Accounts | Google. (n.d.). Service Accounts Overview. Retrieved February 28, 2024. |
| GCP Storage Lifecycles | Google Cloud. (n.d.). Object Lifecycle Management. Retrieved September 25, 2024. |
| GCP gcloud compute disks list | Google Cloud. (n.d.). gcloud compute disks list. Retrieved October 20, 2025. |
| GCPBucketBrute | Spencer Gietzen. (2019, February 26). Google Cloud Platform (GCP) Bucket Enumeration and Privilege Escalation. Retrieved March 4, 2022. |
| GDATA COM Hijacking | G DATA. (2014, October). COM Object hijacking: the discreet way of persistence. Retrieved August 13, 2016. |
| GDATA Zeus Panda June 2017 | Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018. |
| GDS Linux Injection | McNamara, R. (2017, September 5). Linux Based Inter-Process Code Injection Without Ptrace(2). Retrieved February 21, 2020. |
| GLIBC | glibc developer community. (2020, February 1). The GNU C Library (glibc). Retrieved June 25, 2020. |
| GNU Fork | Free Software Foundation, Inc.. (2020, June 18). Creating a Process. Retrieved June 25, 2020. |
| GRIZZLY STEPPE JAR | Department of Homeland Security and Federal Bureau of Investigation. (2016, December 29). GRIZZLY STEPPE – Russian Malicious Cyber Activity. Retrieved January 11, 2017. |
| GTFO split | GTFOBins. (2020, November 13). split. Retrieved April 18, 2022. |
| GTFOBins Docker | GTFOBins. (n.d.). docker. Retrieved February 15, 2024. |
| GTFOBins Suid | Emilio Pinna, Andrea Cardaci. (n.d.). GTFOBins. Retrieved January 28, 2022. |
| GTFObins at | Emilio Pinna, Andrea Cardaci. (n.d.). gtfobins at. Retrieved September 28, 2021. |
| GTIG AI Threat Tracker | Google Threat Intelligence Group . (2026, February 12). GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use. Retrieved March 25, 2026. |
| GWS Apps Script Abuse 2021 | Sergiu Gatlan. (2021, February 18). Hackers abuse Google Apps Script to steal credit cards, bypass CSP. Retrieved July 1, 2024. |
| Gabilondo DYLD_INSERT_LIBRARIES Catalina Bypass | Jon Gabilondo. (2019, September 22). How to Inject Code into Mach-O Apps. Part II.. Retrieved March 24, 2021. |
| Gallagher 2015 | Gallagher, S.. (2015, August 5). Newly discovered Chinese hacking group hacked 100+ websites to use as “watering holes”. Retrieved January 25, 2016. |
| GamaCopy organization | Knownsec 404 Advanced Threat Intelligence team. (2025, January 21). Love and hate under war: The GamaCopy organization, which imitates the Russian Gamaredon, uses military — related bait to launch attacks on Russia. Retrieved June 14, 2025. |
| Ge 2011 | Ge, L. (2011, September 9). BIOS Threat is Showing up Again!. Retrieved November 14, 2014. |
| Gemini FIN7 Oct 2021 | Gemini Advisory. (2021, October 21). FIN7 Recruits Talent For Push Into Ransomware. Retrieved February 2, 2022. |
| Gemini_FIN7_Jan2022 | Gemini Advisory. (2022, January 13). FIN7 Uses Flash Drives to Spread Remote Access Trojan. Retrieved May 14, 2025. |
| Gen Digital Kimsuky HTTPTroy October 2025 | Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026. |
| GenAI Phishing | Adaptive Team. (2025, August 29). Generative AI Phishing: How to Defend in 2025. Retrieved March 26, 2026. |
| GentilKiwi Pass the Ticket | Deply, B. (2014, January 13). Pass the ticket. Retrieved September 12, 2024. |
| Gh0stRAT ATT March 2019 | Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020. |
| GhostToken GCP flaw | Sergiu Gatlan. (2023, April 21). GhostToken GCP flaw let attackers backdoor Google accounts. Retrieved September 18, 2023. |
| Gigamon BADHATCH Jul 2019 | Savelesky, K., et al. (2019, July 23). ABADBABE 8BADFOOD: Discovering BADHATCH and a Detailed Look at FIN8's Tooling. Retrieved September 8, 2021. |
| Gigamon Berserk Bear October 2021 | Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021. |
| GitHub | topotam. (2021, July 18). PetitPotam. PoC tool to coerce Windows hosts to authenticate to other machines. Retrieved May 30, 2025. |
| GitHub ATTACK Empire | Stepanic, D. (2018, September 2). attck_empire: Generate ATT&CK Navigator layer file from PowerShell Empire agent logs. Retrieved March 11, 2019. |
| GitHub AWS-ADFS-Credential-Generator | Damian Hickey. (2017, January 28). AWS-ADFS-Credential-Generator. Retrieved September 27, 2024. |
| GitHub Bloodhound | Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019. |
| GitHub CertStealer | TheWover. (2021, April 21). CertStealer. Retrieved August 2, 2022. |
| GitHub Cloud Service Credentials | Runa A. Sandvik. (2014, January 14). Attackers Scrape GitHub For Cloud Service Credentials, Hijack Account To Mine Virtual Currency. Retrieved August 9, 2022. |
| GitHub Creddump7 | Flathers, R. (2018, February 19). creddump7. Retrieved April 11, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.