Detailedlikelihood: Highseverity: Very HighDraft
CAPEC-37Retrieve Embedded Sensitive Data
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
Very High
Description
An attacker examines a target system to find sensitive data that has been embedded within it. This information can reveal confidential contents, such as account numbers or individual keys/credentials that can be used as an intermediate step in a larger attack.
Metadata: detailed CAPEC pattern, status draft, likelihood high, severity very high. Underlying weaknesses: CWE-226, CWE-311, CWE-525, CWE-312, CWE-314 (and 9 more). Mapped ATT&CK techniques: [object Object], [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 14
MITRE ATT&CK crosswalk· 2
Related attack patterns· 1
Exploits14
Related to2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Private Keyst1552.004 | 100% | live |
| Technique | Data from Local Systemt1005 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.