Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| SANS PsExec | Pilkington, M. (2012, December 17). Protecting Privileged Domain Accounts: PsExec Deep-Dive. Retrieved August 17, 2016. |
| SANS UAC Bypass | Medin, T. (2013, August 8). PsExec UAC Bypass. Retrieved June 3, 2016. |
| SANS Windshift August 2018 | Karim, T. (2018, August). TRAILS OF WINDSHIFT. Retrieved November 17, 2024. |
| SC Magazine Ragnar Locker 2021 | Joe Uchill. (2021, December 3). Ragnar Locker reminds breach victims it can read the on-network incident response chat rooms. Retrieved August 30, 2024. |
| SCADAfence_ransomware | Shaked, O. (2020, January 20). Anatomy of a Targeted Ransomware Attack. Retrieved June 18, 2022. |
| SCILabs Malteiro 2021 | SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024. |
| SCILabs Malteiro Threat Overlap 2023 | SCILabs. (2023, October 8). URSA/Mispadu: Overlap analysis with other threats. Retrieved March 13, 2024. |
| SCILabs URSA/Mispadu Evolution 2023 | SCILabs. (2023, May 23). Evolution of banking trojan URSA/Mispadu. Retrieved March 13, 2024. |
| SE - Hackers Target Workday | David Jones. (2025, August 19). Hackers target Workday in social engineering attack. Retrieved April 15, 2026. |
| SE Proofpoint | Proofpoint. (n.d.). What Is Social Engineering?. Retrieved April 15, 2026. |
| SE SentinelOne | SentinelOne. (2023, October 19). Social Engineering Attacks | How to Recognize and Resist The Bait. Retrieved April 15, 2026. |
| SE SentinelOne 2 | SentinelOne. (2025, August 19). 15 Types of Social Engineering Attacks. Retrieved April 15, 2026. |
| SEC 8-K Stryker Corporation Filing Handala Hack March 2026 | Stryker Corporation. (2026, March 23). SEC 8-K Stryker Corporation. Retrieved April 20, 2026. |
| SEC 8K Palo Alto Statement Stryker Corp Handala March 2026 | Troy Bettencourt. (2026, March 20). SEC 8k: Stryker Corporation Partner and Customer Connections to the Stryker Environment. Retrieved April 20, 2026. |
| SEC EDGAR Search | U.S. SEC. (n.d.). EDGAR - Search and Access. Retrieved November 17, 2024. |
| SECURELIST Bright Star 2015 | Baumgartner, K., Guerrero-Saade, J. (2015, March 4). Who’s Really Spreading through the Bright Star?. Retrieved December 18, 2020. |
| SFX - Encrypted/Encoded File | Jai Minton. (2023, March 31). How Falcon OverWatch Investigates Malicious Self-Extracting Archives, Decoy Files and Their Hidden Payloads. Retrieved March 29, 2024. |
| SIM Swapping and Abuse of the Microsoft Azure Serial Console | Mandiant Intelligence. (2023, May 16). SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack. Retrieved June 2, 2023. |
| SMLoginItemSetEnabled Schroeder 2013 | Tim Schroeder. (2013, April 21). SMLoginItemSetEnabled Demystified. Retrieved November 17, 2024. |
| SOCPrime DoubleExtension | Eugene Tkachenko. (2020, May 1). Rule of the Week: Possible Malicious File Double Extension. Retrieved July 27, 2021. |
| SOCRadar INC Ransom January 2024 | SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024. |
| SOCRadar_MuddyWaterDindoor_Mar2026 | SOCRadar. (2026, March 9). MuddyWater Uses Dindoor Malware Targeting U.S. Networks. Retrieved March 12, 2026. |
| SOCRadar_ShinyHunters_Mar2024 | SOCRadar. (2024, March 18). Dark Web Profile: ShinyHunters. Retrieved May 18, 2026. |
| SPECOPS Outpost24 Handala Hack Stryker March 2026 | David Ketler. (2026, March 30). Stryker Cyber-Attack: What we Know so Far About the Remote Wipe Attack. Retrieved April 20, 2026. |
| SRD GPP | Security Research and Defense. (2014, May 13). MS14-025: An Update for Group Policy Preferences. Retrieved January 28, 2015. |
| SS64 | SS64. (n.d.). ScriptRunner.exe. Retrieved July 8, 2024. |
| SSH Authorized Keys | ssh.com. (n.d.). Authorized_keys File in SSH. Retrieved June 24, 2020. |
| SSH Secure Shell | SSH.COM. (n.d.). SSH (Secure Shell). Retrieved March 23, 2020. |
| SSH Tunneling | SSH.COM. (n.d.). SSH tunnel. Retrieved March 15, 2020. |
| SSH in Windows | Microsoft. (2020, May 19). Tutorial: SSH in Windows Terminal. Retrieved July 26, 2021. |
| SSHjack Blackhat | Adam Boileau. (2005, August 5). Trust Transience: Post Intrusion SSH Hijacking. Retrieved December 19, 2017. |
| SSLShopper Lookup | SSL Shopper. (n.d.). SSL Checker. Retrieved October 20, 2020. |
| SaaS Attacks GitHub Evil Twin Integrations | Push Security. (n.d.). Evil twin integrations. Retrieved March 20, 2025. |
| SafeBreach | Alon Leviev. (2024, August 7). Windows Downdate: Downgrade Attacks Using Windows Updates. Retrieved January 8, 2025. |
| Salesforce zero-day in facebook phishing attack | Bill Toulas. (2023, August 2). Hackers exploited Salesforce zero-day in Facebook phishing attack. Retrieved September 18, 2023. |
| Samba DRSUAPI | SambaWiki. (n.d.). DRSUAPI. Retrieved December 4, 2017. |
| Sandfly BPFDoor 2022 | The Sandfly Security Team. (2022, May 11). BPFDoor - An Evasive Linux Backdoor Technical Analysis. Retrieved September 29, 2023. |
| Sans ARP Spoofing Aug 2003 | Siles, R. (2003, August). Real World ARP Spoofing. Retrieved October 15, 2020. |
| Sans Mutexes 2012 | Lenny Zeltser. (2012, July 24). Looking at Mutex Objects for Malware Discovery & Indicators of Compromise. Retrieved September 19, 2024. |
| Sans Virtual Jan 2016 | Keragala, D. (2016, January 16). Detecting Malware and Sandbox Evasion Techniques. Retrieved April 17, 2019. |
| Savill 1999 | Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015. |
| Scarlet Mimic Jan 2016 | Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016. |
| Schema-abuse | Nick Simonian. (2023, May 22). Don't @ Me: URL Obfuscation Through Schema Abuse. Retrieved February 13, 2024. |
| Schneider Electric USB Malware | Schneider Electric. (2018, August 24). Security Notification – USB Removable Media Provided With Conext Combox and Conext Battery Monitor. Retrieved May 28, 2019. |
| ScriptingOSX zsh | Armin Briegel. (2019, June 5). Moving to zsh, part 2: Configuration Files. Retrieved February 25, 2021. |
| Sean Metcalf Twitter DNS Records | Sean Metcalf. (2019, May 9). Sean Metcalf Twitter. Retrieved September 12, 2024. |
| SecTools nbtscan June 2003 | SecTools. (2003, June 11). NBTscan. Retrieved March 17, 2021. |
| Secpod Winexe June 2017 | Prakash, T. (2017, June 21). Run commands on Windows system remotely using Winexe. Retrieved September 12, 2024. |
| Secure Ideas SMB Relay | Kuehn, E. (2018, April 11). Ever Run a Relay? Why SMB Relays Should Be On Your Mind. Retrieved February 7, 2019. |
| Secure List Bad Rabbit | Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.