Detailedlikelihood: Mediumseverity: MediumDraft
CAPEC-643Identify Shared Files/Directories on System
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
Medium
Description
An adversary discovers connections between systems by exploiting the target system's standard practice of revealing them in searchable, common areas. Through the identification of shared folders/drives between systems, the adversary may further their goals of locating and collecting sensitive information/files, or map potential routes for lateral movement within the network.
Related weaknesses· 2
MITRE ATT&CK crosswalk· 1
Related attack patterns· 4
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 100% | live |
| Weakness | Privilege Defined With Unsafe Actionscwe-267 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Network Share Discoveryt1135 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.