Detailedlikelihood: Mediumseverity: MediumDraft
CAPEC-647Collect Data from Registries
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
Medium
Description
An adversary exploits a weakness in authorization to gather system-specific data and sensitive information within a registry (e.g., Windows Registry, Mac plist). These contain information about the system configuration, software, operating system, and security. The adversary can leverage information gathered in order to carry out further attacks.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 3
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authorizationcwe-285 | 100% | live |
Related to3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Query Registryt1012 | 100% | live |
| Technique | Data from Local Systemt1005 | 100% | live |
| SubTechnique | Credentials in Registryt1552.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.