Standardseverity: Very HighStable
CAPEC-555Remote Services with Stolen Credentials
Abstraction
Standard
Status
Stable
Severity
Very High
Description
This pattern of attack involves an adversary that uses stolen credentials to leverage remote services such as RDP, telnet, SSH, and VNC to log into a system. Once access is gained, any number of malicious activities could be performed.
Metadata: standard CAPEC pattern, status stable, severity very high. Underlying weaknesses: CWE-522, CWE-308, CWE-309, CWE-294, CWE-263 (and 2 more). Mapped ATT&CK techniques: [object Object], [object Object], [object Object]. Related CAPEC patterns: [object Object], [object Object].
Related weaknesses· 7
MITRE ATT&CK crosswalk· 3
Related attack patterns· 2
Exploits7
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Password Aging with Long Expirationcwe-263 | 100% | live |
| Weakness | Not Using Password Agingcwe-262 | 100% | live |
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
| Weakness | Weak Password Requirementscwe-521 | 100% | live |
| Weakness | Use of Password System for Primary Authenticationcwe-309 | 100% | live |
| Weakness | Authentication Bypass by Capture-replaycwe-294 | 100% | live |
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
Related to3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | External Remote Servicest1133 | 100% | live |
| Technique | Remote Servicest1021 | 100% | live |
| SubTechnique | Remote Email Collectiont1114.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.