ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
SANS PsExecPilkington, M. (2012, December 17). Protecting Privileged Domain Accounts: PsExec Deep-Dive. Retrieved August 17, 2016.
SANS UAC BypassMedin, T. (2013, August 8). PsExec UAC Bypass. Retrieved June 3, 2016.
SANS Windshift August 2018Karim, T. (2018, August). TRAILS OF WINDSHIFT. Retrieved November 17, 2024.
SC Magazine Ragnar Locker 2021Joe Uchill. (2021, December 3). Ragnar Locker reminds breach victims it can read the on-network incident response chat rooms. Retrieved August 30, 2024.
SCADAfence_ransomwareShaked, O. (2020, January 20). Anatomy of a Targeted Ransomware Attack. Retrieved June 18, 2022.
SCILabs Malteiro 2021SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.
SCILabs Malteiro Threat Overlap 2023SCILabs. (2023, October 8). URSA/Mispadu: Overlap analysis with other threats. Retrieved March 13, 2024.
SCILabs URSA/Mispadu Evolution 2023SCILabs. (2023, May 23). Evolution of banking trojan URSA/Mispadu. Retrieved March 13, 2024.
SE - Hackers Target WorkdayDavid Jones. (2025, August 19). Hackers target Workday in social engineering attack. Retrieved April 15, 2026.
SE ProofpointProofpoint. (n.d.). What Is Social Engineering?. Retrieved April 15, 2026.
SE SentinelOneSentinelOne. (2023, October 19). Social Engineering Attacks | How to Recognize and Resist The Bait. Retrieved April 15, 2026.
SE SentinelOne 2SentinelOne. (2025, August 19). 15 Types of Social Engineering Attacks. Retrieved April 15, 2026.
SEC 8-K Stryker Corporation Filing Handala Hack March 2026Stryker Corporation. (2026, March 23). SEC 8-K Stryker Corporation. Retrieved April 20, 2026.
SEC 8K Palo Alto Statement Stryker Corp Handala March 2026Troy Bettencourt. (2026, March 20). SEC 8k: Stryker Corporation Partner and Customer Connections to the Stryker Environment. Retrieved April 20, 2026.
SEC EDGAR SearchU.S. SEC. (n.d.). EDGAR - Search and Access. Retrieved November 17, 2024.
SECURELIST Bright Star 2015Baumgartner, K., Guerrero-Saade, J. (2015, March 4). Who’s Really Spreading through the Bright Star?. Retrieved December 18, 2020.
SFX - Encrypted/Encoded FileJai Minton. (2023, March 31). How Falcon OverWatch Investigates Malicious Self-Extracting Archives, Decoy Files and Their Hidden Payloads. Retrieved March 29, 2024.
SIM Swapping and Abuse of the Microsoft Azure Serial ConsoleMandiant Intelligence. (2023, May 16). SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack. Retrieved June 2, 2023.
SMLoginItemSetEnabled Schroeder 2013Tim Schroeder. (2013, April 21). SMLoginItemSetEnabled Demystified. Retrieved November 17, 2024.
SOCPrime DoubleExtensionEugene Tkachenko. (2020, May 1). Rule of the Week: Possible Malicious File Double Extension. Retrieved July 27, 2021.
SOCRadar INC Ransom January 2024SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
SOCRadar_MuddyWaterDindoor_Mar2026SOCRadar. (2026, March 9). MuddyWater Uses Dindoor Malware Targeting U.S. Networks. Retrieved March 12, 2026.
SOCRadar_ShinyHunters_Mar2024SOCRadar. (2024, March 18). Dark Web Profile: ShinyHunters. Retrieved May 18, 2026.
SPECOPS Outpost24 Handala Hack Stryker March 2026David Ketler. (2026, March 30). Stryker Cyber-Attack: What we Know so Far About the Remote Wipe Attack. Retrieved April 20, 2026.
SRD GPPSecurity Research and Defense. (2014, May 13). MS14-025: An Update for Group Policy Preferences. Retrieved January 28, 2015.
SS64SS64. (n.d.). ScriptRunner.exe. Retrieved July 8, 2024.
SSH Authorized Keysssh.com. (n.d.). Authorized_keys File in SSH. Retrieved June 24, 2020.
SSH Secure ShellSSH.COM. (n.d.). SSH (Secure Shell). Retrieved March 23, 2020.
SSH TunnelingSSH.COM. (n.d.). SSH tunnel. Retrieved March 15, 2020.
SSH in WindowsMicrosoft. (2020, May 19). Tutorial: SSH in Windows Terminal. Retrieved July 26, 2021.
SSHjack BlackhatAdam Boileau. (2005, August 5). Trust Transience: Post Intrusion SSH Hijacking. Retrieved December 19, 2017.
SSLShopper LookupSSL Shopper. (n.d.). SSL Checker. Retrieved October 20, 2020.
SaaS Attacks GitHub Evil Twin IntegrationsPush Security. (n.d.). Evil twin integrations. Retrieved March 20, 2025.
SafeBreachAlon Leviev. (2024, August 7). Windows Downdate: Downgrade Attacks Using Windows Updates. Retrieved January 8, 2025.
Salesforce zero-day in facebook phishing attackBill Toulas. (2023, August 2). Hackers exploited Salesforce zero-day in Facebook phishing attack. Retrieved September 18, 2023.
Samba DRSUAPISambaWiki. (n.d.). DRSUAPI. Retrieved December 4, 2017.
Sandfly BPFDoor 2022The Sandfly Security Team. (2022, May 11). BPFDoor - An Evasive Linux Backdoor Technical Analysis. Retrieved September 29, 2023.
Sans ARP Spoofing Aug 2003Siles, R. (2003, August). Real World ARP Spoofing. Retrieved October 15, 2020.
Sans Mutexes 2012Lenny Zeltser. (2012, July 24). Looking at Mutex Objects for Malware Discovery & Indicators of Compromise. Retrieved September 19, 2024.
Sans Virtual Jan 2016Keragala, D. (2016, January 16). Detecting Malware and Sandbox Evasion Techniques. Retrieved April 17, 2019.
Savill 1999Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Scarlet Mimic Jan 2016Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.
Schema-abuseNick Simonian. (2023, May 22). Don't @ Me: URL Obfuscation Through Schema Abuse. Retrieved February 13, 2024.
Schneider Electric USB MalwareSchneider Electric. (2018, August 24). Security Notification – USB Removable Media Provided With Conext Combox and Conext Battery Monitor. Retrieved May 28, 2019.
ScriptingOSX zshArmin Briegel. (2019, June 5). Moving to zsh, part 2: Configuration Files. Retrieved February 25, 2021.
Sean Metcalf Twitter DNS RecordsSean Metcalf. (2019, May 9). Sean Metcalf Twitter. Retrieved September 12, 2024.
SecTools nbtscan June 2003SecTools. (2003, June 11). NBTscan. Retrieved March 17, 2021.
Secpod Winexe June 2017Prakash, T. (2017, June 21). Run commands on Windows system remotely using Winexe. Retrieved September 12, 2024.
Secure Ideas SMB RelayKuehn, E. (2018, April 11). Ever Run a Relay? Why SMB Relays Should Be On Your Mind. Retrieved February 7, 2019.
Secure List Bad RabbitMamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.