Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| PoetRat Lua | Mercer, Warren. (2020, October 6). PoetRAT: Malware targeting public and private sector in Azerbaijan evolves. Retrieved August 5, 2024. |
| Polak NPPSPY 2004 | Sergey Polak. (2004, August). Capturing Windows Passwords using the Network Provider API. Retrieved May 17, 2024. |
| Polop Linux PrivEsc Gitbook | Carlos Polop. (2023, March 5). Linux Privilege Escalation. Retrieved March 31, 2023. |
| Positive Technologies Hellhounds 2023 | PT Expert Security Center. (2023, November 29). Hellhounds: operation Lahat. Retrieved March 18, 2025. |
| PowerShell About 2019 | Wheeler, S. et al.. (2019, May 1). About PowerShell.exe. Retrieved October 11, 2019. |
| PowerShellMagazine PowerSploit July 2014 | Graeber, M. (2014, July 8). PowerSploit. Retrieved February 6, 2018. |
| PowerSploit Documentation | PowerSploit. (n.d.). PowerSploit. Retrieved February 6, 2018. |
| PowerSploit Invoke Kerberoast | Schroeder, W. & Hart M. (2016, October 31). Invoke-Kerberoast. Retrieved March 23, 2018. |
| Powershell Remote Commands | Microsoft. (2020, August 21). Running Remote Commands. Retrieved July 26, 2021. |
| Praetorian TLS Downgrade Attack 2014 | Praetorian. (2014, August 19). Man-in-the-Middle TLS Protocol Downgrade Attack. Retrieved October 8, 2021. |
| Prevailion DarkWatchman 2021 | Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022. |
| Prevailion EvilNum May 2020 | Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024. |
| Prevx Carberp March 2011 | Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024. |
| ProcessHacker Github | ProcessHacker. (2009, October 27). Process Hacker. Retrieved April 11, 2022. |
| Profero APT27 December 2020 | Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021. |
| ProjectZero File Write EoP Apr 2018 | Forshaw, J. (2018, April 18). Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevation of Privilege. Retrieved May 3, 2018. |
| ProofPoint GoT 9002 Aug 2017 | Huss, D. & Mesa, M. (2017, August 25). Operation RAT Cook: Chinese APT actors use fake Game of Thrones leaks as lures. Retrieved March 19, 2018. |
| ProofPoint Serpent | Campbell, B. et al. (2022, March 21). Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain. Retrieved April 11, 2022. |
| ProofPoint SettingContent-ms July 2018 | Proofpoint Staff. (2018, July 19). TA505 Abusing SettingContent-ms within PDF files to Distribute FlawedAmmyy RAT. Retrieved April 19, 2019. |
| ProofPoint Ursnif Aug 2016 | Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019. |
| Proofpoint Azorult July 2018 | Proofpoint. (2018, July 30). New version of AZORult stealer improves loading features, spreads alongside ransomware in new campaign. Retrieved November 29, 2018. |
| Proofpoint Bumblebee April 2022 | Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022. |
| Proofpoint ClickFix 2024 | Tommy Madjar, Selena Larson and The Proofpoint Threat Research Team. (2024, November 18). Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape. Retrieved March 18, 2025. |
| Proofpoint Cobalt June 2017 | Mesa, M, et al. (2017, June 1). Microsoft Word Intruder Integrates CVE-2017-0199, Utilized by Cobalt Group to Target Financial Institutions. Retrieved October 10, 2018. |
| Proofpoint Domain Shadowing | Proofpoint Staff. (2015, December 15). The shadow knows: Malvertising campaigns use domain shadowing to pull in Angler EK. Retrieved October 16, 2020. |
| Proofpoint Human Factor | Proofpoint. (n.d.). The Human Factor 2023: Analyzing the cyber attack chain. Retrieved July 20, 2023. |
| Proofpoint Leviathan Oct 2017 | Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018. |
| Proofpoint LookBack Malware Aug 2019 | Raggi, M. Schwarz, D.. (2019, August 1). LookBack Malware Targets the United States Utilities Sector with Phishing Attacks Impersonating Engineering Licensing Boards. Retrieved February 25, 2021. |
| Proofpoint NETWIRE December 2020 | Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021. |
| Proofpoint Operation Transparent Tribe March 2016 | Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016. |
| Proofpoint RTF Injection | Raggi, M. (2021, December 1). Injection is the New Black: Novel RTF Template Inject Technique Poised for Widespread Adoption Beyond APT Actors . Retrieved December 9, 2021. |
| Proofpoint RedLine Stealer March 2020 | Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025. |
| Proofpoint Router Malvertising | Kafeine. (2016, December 13). Home Routers Under Attack via Malvertising on Windows, Android Devices. Retrieved January 16, 2019. |
| Proofpoint TA2541 February 2022 | Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023. |
| Proofpoint TA407 September 2019 | Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021. |
| Proofpoint TA416 Europe March 2022 | Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022. |
| Proofpoint TA416 November 2020 | Proofpoint Threat Research Team. (2020, November 23). TA416 Goes to Ground and Returns with a Golang PlugX Malware Loader. Retrieved April 13, 2021. |
| Proofpoint TA427 April 2024 | Lesnewich, G. et al. (2024, April 16). From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering. Retrieved May 3, 2024. |
| Proofpoint TA450 Phishing March 2024 | Miller, J. et al. (2024, March 21). Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign. Retrieved March 27, 2024. |
| Proofpoint TA453 July2021 | Miller, J. et al. (2021, July 13). Operation SpoofedScholars: A Conversation with TA453. Retrieved August 18, 2021. |
| Proofpoint TA453 March 2021 | Miller, J. et al. (2021, March 30). BadBlood: TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns. Retrieved May 4, 2021. |
| Proofpoint TA459 April 2017 | Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018. |
| Proofpoint TA505 Jan 2019 | Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019. |
| Proofpoint TA505 June 2018 | Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019. |
| Proofpoint TA505 Mar 2018 | Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019. |
| Proofpoint TA505 October 2019 | Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020. |
| Proofpoint TA505 Sep 2017 | Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019. |
| Proofpoint Vega Credential Stealer May 2018 | Proofpoint. (2018, May 10). New Vega Stealer shines brightly in targeted campaign . Retrieved June 18, 2019. |
| Proofpoint Vishing | Proofpoint. (n.d.). What Is Vishing?. Retrieved September 8, 2023. |
| Proofpoint WinterVivern 2023 | Michael Raggi & The Proofpoint Threat Research Team. (2023, March 30). Exploitation is a Dish Best Served Cold: Winter Vivern Uses Known Zimbra Vulnerability to Target Webmail Portals of NATO-Aligned Governments in Europe. Retrieved July 2… |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.