Standardlikelihood: Highseverity: Very LowDraft
CAPEC-497File Discovery
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
Very Low
Description
An adversary engages in probing and exploration activities to determine if common key files exists. Such files often contain configuration and security parameters of the targeted application, system or network. Using this knowledge may often pave the way for more damaging attacks.
Metadata: standard CAPEC pattern, status draft, likelihood high, severity very low. Underlying weakness: CWE-200. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | File and Directory Discoveryt1083 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.