Standardseverity: MediumDraft
CAPEC-150Collect Data from Common Resource Locations
Abstraction
Standard
Status
Draft
Severity
Medium
Description
An adversary exploits well-known locations for resources for the purposes of undermining the security of the target. In many, if not most systems, files and resources are organized in a default tree structure. This can be useful for adversaries because they often know where to look for resources or files that are necessary for attacks. Even when the precise location of a targeted resource may not be known, naming conventions may indicate a small area of the target machine's file tree where the resources are typically located. For example, configuration files are normally stored in the /etc director on Unix systems. Adversaries can take advantage of this to commit other types of attacks.
Related weaknesses· 7
MITRE ATT&CK crosswalk· 6
Related attack patterns· 1
Exploits7
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Remanent Data Readable after Memory Erasecwe-1330 | 100% | live |
| Weakness | Improper Zeroization of Hardware Registercwe-1239 | 100% | live |
| Weakness | Improper Management of Sensitive Trace Datacwe-1323 | 100% | live |
| Weakness | Sensitive Information Uncleared Before Debug/Power State Transitioncwe-1272 | 100% | live |
| Weakness | Exposure of Sensitive System Information Due to Uncleared Debug Informationcwe-1258 | 100% | live |
| Weakness | Files or Directories Accessible to External Partiescwe-552 | 100% | live |
| Weakness | Improper Scrubbing of Sensitive Data from Decommissioned Devicecwe-1266 | 100% | live |
Related to6
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Automated Collectiont1119 | 100% | live |
| Technique | Data from Configuration Repositoryt1602 | 100% | live |
| Technique | Credentials from Password Storest1555 | 100% | live |
| Technique | OS Credential Dumpingt1003 | 100% | live |
| Technique | Data from Cloud Storaget1530 | 100% | live |
| Technique | Data from Information Repositoriest1213 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.