615 indexed

CAPECCAPEC attack patterns

615 MITRE CAPEC entries — attack patterns at meta, standard, and detailed abstraction levels. Filter by abstraction. Authored by Adam Lundqvist.

Showing 151–200 of 341 in Detailed · page 4 of 7

IDTitleSummary
CAPEC-420Influence Perception of ScarcityThe adversary leverages a perception of scarcity to persuade the target to perform an action or divulge information that is advantageous to the adversary. By c…
CAPEC-421Influence Perception of AuthorityAn adversary uses a social engineering technique to convey a sense of authority that motivates the target to reveal specific information or take specific actio…
CAPEC-422Influence Perception of Commitment and ConsistencyAn adversary uses social engineering to convince the target to do minor tasks as opposed to larger actions. After complying with a request, individuals are mor…
CAPEC-423Influence Perception of LikingThe adversary influences the target's actions by building a relationship where the target has a liking to the adversary. People are more likely to be influence…
CAPEC-424Influence Perception of Consensus or Social ProofThe adversary influences the target's actions by leveraging the inherent human nature to assume behavior of others is appropriate. In situations of uncertainty…
CAPEC-428Influence via Modes of ThinkingThe adversary tailors their communication to the language and thought patterns of the target thereby weakening barriers or reluctance to communication. This me…
CAPEC-429Target Influence via Eye CuesThe adversary gains information via non-verbal means from the target through eye movements. Metadata: detailed CAPEC pattern, status draft, severity low. Rela…
CAPEC-43Exploiting Multiple Input Interpretation LayersAn attacker supplies the target software with input data that contains sequences of special characters designed to bypass input validation logic. This exploit …
CAPEC-430DEPRECATED: Target Influence via Micro-ExpressionsThis attack pattern has been deprecated. Metadata: detailed CAPEC pattern, status deprecated. Metadata: detailed CAPEC pattern, status deprecated.
CAPEC-431DEPRECATED: Target Influence via Neuro-Linguistic Programming (NLP)This attack pattern has been deprecated. Metadata: detailed CAPEC pattern, status deprecated. Metadata: detailed CAPEC pattern, status deprecated.
CAPEC-432DEPRECATED: Target Influence via Voice in NLPThis attack pattern has been deprecated. Metadata: detailed CAPEC pattern, status deprecated. Metadata: detailed CAPEC pattern, status deprecated.
CAPEC-433Target Influence via The Human Buffer OverflowAn attacker utilizes a technique to insinuate commands to the subconscious mind of the target via communication patterns. The human buffer overflow methodology…
CAPEC-434Target Influence via Interview and InterrogationMetadata: detailed CAPEC pattern, status draft, severity low. Related CAPEC pattern: [object Object]. Metadata: detailed CAPEC pattern, status draft, severity…
CAPEC-435Target Influence via Instant RapportMetadata: detailed CAPEC pattern, status draft, severity low. Related CAPEC pattern: [object Object]. Metadata: detailed CAPEC pattern, status draft, severity…
CAPEC-44Overflow Binary Resource FileAn attack of this type exploits a buffer overflow vulnerability in the handling of binary resources. Binary resources may include music files like MP3, image f…
CAPEC-443Malicious Logic Inserted Into Product by Authorized DeveloperAn adversary uses their privileged position within an authorized development organization to inject malicious logic into a codebase or product. Metadata: deta…
CAPEC-445Malicious Logic Insertion into Product Software via Configuration Management ManipulationMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Obj…
CAPEC-446Malicious Logic Insertion into Product via Inclusion of Third-Party ComponentMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Obj…
CAPEC-448Embed Virus into DLLAn adversary tampers with a DLL and embeds a computer virus into gaps between legitimate machine instructions. These gaps may be the result of compiler optimiz…
CAPEC-449DEPRECATED: Malware Propagation via USB StickThis attack pattern has been deprecated as it is a duplicate of CAPEC-448 : Malware Infection into Product Software. Please refer to this other pattern going f…
CAPEC-45Buffer Overflow via Symbolic LinksThis type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulate a symbolic link file such that …
CAPEC-451DEPRECATED: Malware Propagation via Infected Peripheral DeviceThis attack pattern has been deprecated as it is a duplicate of CAPEC-448 : Malware Infection into Product Software. Please refer to this other pattern going f…
CAPEC-454DEPRECATED: Modification of Existing Components with Counterfeit HardwareThis attack pattern has been deprecated as it is a duplicate of CAPEC-452 : Malicious Logic Insertion into Product Hardware. Please refer to this other pattern…
CAPEC-455DEPRECATED: Malicious Logic Insertion via Inclusion of Counterfeit Hardware ComponentsThis attack pattern has been deprecated as it is a duplicate of CAPEC-457 : Malicious Logic Insertion into Product Hardware. Please refer to this other pattern…
CAPEC-457USB Memory AttacksAn adversary loads malicious code onto a USB memory stick in order to infect any system which the device is plugged in to. USB drives present a significant sec…
CAPEC-458Flash Memory AttacksAn adversary inserts malicious logic into a product or technology via flashing the on-board memory with a code-base that contains malicious logic. Various atta…
CAPEC-459Creating a Rogue Certification Authority CertificateAn adversary exploits a weakness resulting from using a hashing algorithm with weak collision resistance to generate certificate signing requests (CSR) that co…
CAPEC-46Overflow Variables and TagsThis type of attack leverages the use of tags or variables from a formatted configuration data to cause buffer overflow. The adversary crafts a malicious HTML …
CAPEC-460HTTP Parameter Pollution (HPP)An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override existing hardcoded HTTP param…
CAPEC-462Cross-Domain Search TimingAn attacker initiates cross domain HTTP / GET requests and times the server responses. The timing of these responses may leak important information on what is …
CAPEC-463Padding Oracle Crypto AttackAn adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened wh…
CAPEC-467Cross Site IdentificationAn attacker harvests identifying information about a victim via an active session that the victim's browser has with a social networking site. A victim may hav…
CAPEC-47Buffer Overflow via Parameter ExpansionIn this attack, the target software is given input that the adversary knows will be modified and expanded in size during processing. This attack relies on the …
CAPEC-470Expanding Control over the Operating System from the DatabaseAn attacker is able to leverage access gained to the database to read / write data to the file system, compromise the operating system, create a tunnel for acc…
CAPEC-471Search Order HijackingAn adversary exploits a weakness in an application's specification of external libraries to exploit the functionality of the loader where the process loading t…
CAPEC-472Browser FingerprintingAn attacker carefully crafts small snippets of Java Script to efficiently detect the type of browser the potential victim is using. Many web-based attacks need…
CAPEC-474Signature Spoofing by Key TheftAn attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to forge signatures from the original signer t…
CAPEC-475Signature Spoofing by Improper ValidationAn adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key. M…
CAPEC-476Signature Spoofing by MisrepresentationAn attacker exploits a weakness in the parsing or display code of the recipient software to generate a data blob containing a supposedly valid signature, but t…
CAPEC-477Signature Spoofing by Mixing Signed and Unsigned ContentAn attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as …
CAPEC-478Modification of Windows Service ConfigurationAn adversary exploits a weakness in access control to modify the execution parameters of a Windows service. The goal of this attack is to execute a malicious b…
CAPEC-479Malicious Root CertificateAn adversary exploits a weakness in authorization and installs a new root certificate on a compromised system. Certificates are commonly used for establishing …
CAPEC-485Signature Spoofing by Key RecreationAn attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudoran…
CAPEC-491Quadratic Data ExpansionAn adversary exploits macro-like substitution to cause a denial of service situation due to excessive memory being allocated to fully expand the data. The resu…
CAPEC-498Probe iOS ScreenshotsAn adversary examines screenshot images created by iOS in an attempt to obtain sensitive information. This attack targets temporary screenshots created by the …
CAPEC-5Blue BoxingMetadata: detailed CAPEC pattern, status obsolete, likelihood medium, severity very high. Underlying weakness: CWE-285. Related CAPEC pattern: [object Object].…
CAPEC-500WebView InjectionAn adversary, through a previously installed malicious application, injects code into the context of a web page displayed by a WebView component. Through the i…
CAPEC-501Android Activity HijackAn adversary intercepts an implicit intent sent to launch a Android-based trusted activity and instead launches a counterfeit activity in its place. The malici…
CAPEC-505Scheme SquattingAn adversary, through a previously installed malicious application, registers for a URL scheme intended for a target application that has not been installed. T…
CAPEC-508Shoulder SurfingIn a shoulder surfing attack, an adversary observes an unaware individual's keystrokes, screen content, or conversations with the goal of obtaining sensitive i…
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, Founder at SQUR.
MITRE CAPEC attack patterns — by abstraction | SQUR Knowledge Base