DetailedDraft
CAPEC-561Windows Admin Shares with Stolen Credentials
Abstraction
Detailed
Status
Draft
Description
An adversary guesses or obtains (i.e. steals or purchases) legitimate Windows administrator credentials (e.g. userID/password) to access Windows Admin Shares on a local machine or within a Windows domain.
Metadata: detailed CAPEC pattern, status draft. Underlying weaknesses: CWE-522, CWE-308, CWE-309, CWE-294, CWE-263 (and 2 more). Mapped ATT&CK technique: [object Object]. Related CAPEC patterns: [object Object], [object Object], [object Object], [object Object] (and 1 more).
Related weaknesses· 7
MITRE ATT&CK crosswalk· 1
Related attack patterns· 5
Exploits7
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
| Weakness | Authentication Bypass by Capture-replaycwe-294 | 100% | live |
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
| Weakness | Not Using Password Agingcwe-262 | 100% | live |
| Weakness | Weak Password Requirementscwe-521 | 100% | live |
| Weakness | Password Aging with Long Expirationcwe-263 | 100% | live |
| Weakness | Use of Password System for Primary Authenticationcwe-309 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | SMB/Windows Admin Sharest1021.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.