Detailedseverity: MediumStable
CAPEC-639Probe System Files
Abstraction
Detailed
Status
Stable
Severity
Medium
Description
An adversary obtains unauthorized information due to improperly protected files. If an application stores sensitive information in a file that is not protected by proper access control, then an adversary can access the file and search for sensitive information.
Metadata: detailed CAPEC pattern, status stable, severity medium. Underlying weakness: CWE-552. Mapped ATT&CK techniques: [object Object], [object Object], [object Object], [object Object], [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 5
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Files or Directories Accessible to External Partiescwe-552 | 100% | live |
Related to5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Data from Network Shared Drivet1039 | 100% | live |
| SubTechnique | Credentials In Filest1552.001 | 100% | live |
| SubTechnique | Bash Historyt1552.003 | 100% | live |
| SubTechnique | Private Keyst1552.004 | 100% | live |
| SubTechnique | Group Policy Preferencest1552.006 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.