615 indexed

CAPECCAPEC attack patterns

615 MITRE CAPEC entries — attack patterns at meta, standard, and detailed abstraction levels. Filter by abstraction. Authored by Adam Lundqvist.

Showing 101–150 of 197 in Standard · page 3 of 4

IDTitleSummary
CAPEC-481Contradictory Destinations in Traffic Routing SchemesAdversaries can provide contradictory destinations when sending messages. Traffic is routed in networks using the domain names in various headers available at …
CAPEC-482TCP FloodAn adversary may execute a flooding attack using the TCP protocol with the intent to deny legitimate users access to a service. These attacks exploit the weakn…
CAPEC-484DEPRECATED: XML Client-Side AttackThis attack pattern has been deprecated as it a generalization of CAPEC-230: XML Nested Payloads and CAPEC-231: XML Oversized Payloads. Please refer to these C…
CAPEC-486UDP FloodAn adversary may execute a flooding attack using the UDP protocol with the intent to deny legitimate users access to a service by consuming the available netwo…
CAPEC-487ICMP FloodAn adversary may execute a flooding attack using the ICMP protocol with the intent to deny legitimate users access to a service by consuming the available netw…
CAPEC-488HTTP FloodAn adversary may execute a flooding attack using the HTTP protocol with the intent to deny legitimate users access to a service by consuming resources at the a…
CAPEC-489SSL FloodAn adversary may execute a flooding attack using the SSL protocol with the intent to deny legitimate users access to a service by consuming all the available r…
CAPEC-49Password Brute ForcingAn adversary tries every possible value for a password until they succeed. A brute force attack, if feasible computationally, will always be successful because…
CAPEC-490AmplificationAn adversary may execute an amplification where the size of a response is far greater than that of the request that generates it. The goal of this attack is to…
CAPEC-492Regular Expression Exponential BlowupAn adversary may execute an attack on a program that uses a poor Regular Expression(Regex) implementation by choosing input that results in an extreme situatio…
CAPEC-493SOAP Array BlowupAn adversary may execute an attack on a web service that uses SOAP messages in communication. By sending a very large SOAP array declaration to the web service…
CAPEC-494TCP FragmentationAn adversary may execute a TCP Fragmentation attack against a target with the intention of avoiding filtering rules of network controls, by attempting to fragm…
CAPEC-495UDP FragmentationAn attacker may execute a UDP Fragmentation attack against a target server in an attempt to consume resources such as bandwidth and CPU. IP fragmentation occur…
CAPEC-496ICMP FragmentationAn attacker may execute a ICMP Fragmentation attack against a target with the intention of consuming resources or causing a crash. The attacker crafts a large …
CAPEC-497File DiscoveryAn adversary engages in probing and exploration activities to determine if common key files exists. Such files often contain configuration and security paramet…
CAPEC-499Android Intent InterceptAn adversary, through a previously installed malicious application, intercepts messages from a trusted Android-based application in an attempt to achieve a var…
CAPEC-50Password Recovery ExploitationAn attacker may take advantage of the application feature to help users recover their forgotten passwords in order to gain access into the system with the same…
CAPEC-502Intent SpoofAn adversary, through a previously installed malicious application, issues an intent directed toward a specific trusted application's component in an attempt t…
CAPEC-503WebView ExposureAn adversary, through a malicious web page, accesses application specific functionality by leveraging interfaces registered through WebView's addJavascriptInte…
CAPEC-504Task ImpersonationAn adversary, through a previously installed malicious application, impersonates an expected or routine task in an attempt to steal sensitive information or le…
CAPEC-506TapjackingAn adversary, through a previously installed malicious application, displays an interface that misleads the user and convinces them to tap on an attacker desir…
CAPEC-510SaaS User Request ForgeryAn adversary, through a previously installed malicious application, performs malicious actions against a third-party Software as a Service (SaaS) application (…
CAPEC-522Malicious Hardware Component ReplacementAn adversary replaces legitimate hardware in the system with faulty counterfeit or tampered hardware in the supply chain distribution channel, with purpose of …
CAPEC-523Malicious Software ImplantedAn attacker implants malicious software into the system in the supply chain distribution channel, with purpose of causing malicious disruption or allowing for …
CAPEC-524Rogue Integration ProceduresAn attacker alters or establishes rogue processes in an integration facility in order to insert maliciously altered components into the system. The attacker wo…
CAPEC-528XML FloodAn adversary may execute a flooding attack using XML messages with the intent to deny legitimate users access to a web service. These attacks are accomplished …
CAPEC-529Malware-Directed Internal ReconnaissanceAdversary uses malware or a similarly controlled application installed inside an organizational perimeter to gather information about the composition, configur…
CAPEC-534Malicious Hardware UpdateAn adversary introduces malicious hardware during an update or replacement procedure, allowing for additional compromise or site disruption at the victim locat…
CAPEC-536Data Injected During ConfigurationAn attacker with access to data files and processes on a victim's system injects malicious data into critical operational data during configuration or recalibr…
CAPEC-54Query System for InformationAn adversary, aware of an application's location (and possibly authorized to use the application), probes an application's structure and evaluates its robustne…
CAPEC-540Overread BuffersAn adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value…
CAPEC-541Application FingerprintingAn adversary engages in fingerprinting activities to determine the type or version of an application installed on a remote target. Metadata: standard CAPEC pa…
CAPEC-542Targeted MalwareAn adversary develops targeted malware that takes advantage of a known vulnerability in an organizational information technology environment. The malware craft…
CAPEC-545Pull Data from System ResourcesAn adversary who is authorized or has the ability to search known system resources, does so with the intention of gathering useful information. System resource…
CAPEC-547Physical Destruction of Device or ComponentAn adversary conducts a physical attack a device or component, destroying it such that it no longer functions as intended. Metadata: standard CAPEC pattern, s…
CAPEC-555Remote Services with Stolen CredentialsThis pattern of attack involves an adversary that uses stolen credentials to leverage remote services such as RDP, telnet, SSH, and VNC to log into a system. O…
CAPEC-56DEPRECATED: Removing/short-circuiting 'guard logic'This attack pattern has been deprecated as it is a duplicate of CAPEC-207 : Removing Important Client Functionality. Please refer to this other pattern going f…
CAPEC-567DEPRECATED: Obtain Data via UtilitiesThis CAPEC has been deprecated because it is not directly related to a weakness, social engineering, supply chains, or a physical-based attack. Metadata: stan…
CAPEC-569Collect Data as Provided by UsersAn attacker leverages a tool, device, or program to obtain specific information as provided by a user of the target system. This information is often needed by…
CAPEC-571Block Logging to Central RepositoryMetadata: standard CAPEC pattern, status draft, severity low. Mapped ATT&CK techniques: [object Object], [object Object], [object Object], [object Object]. Rel…
CAPEC-572Artificially Inflate File SizesMetadata: standard CAPEC pattern, status draft, likelihood high, severity medium. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Obje…
CAPEC-573Process FootprintingAn adversary exploits functionality meant to identify information about the currently running processes on the target system to an authorized user. By knowing …
CAPEC-574Services FootprintingAn adversary exploits functionality meant to identify information about the services on the target system to an authorized user. By knowing what services are r…
CAPEC-575Account FootprintingAn adversary exploits functionality meant to identify information about the domain accounts and their permissions on the target system to an authorized user. B…
CAPEC-576Group Permission FootprintingAn adversary exploits functionality meant to identify information about user groups and their permissions on the target system to an authorized user. By knowin…
CAPEC-577Owner FootprintingAn adversary exploits functionality meant to identify information about the primary users on the target system to an authorized user. They may do this, for exa…
CAPEC-578Disable Security SoftwareAn adversary exploits a weakness in access control to disable security tools so that detection does not occur. This can take the form of killing processes, del…
CAPEC-580System FootprintingAn adversary engages in active probing and exploration activities to determine security information about a remote target system. Often times adversaries will …
CAPEC-582Route DisablingAn adversary disables the network route between two targets. The goal is to completely sever the communications channel between two entities. This is often the…
CAPEC-593Session HijackingThis type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to s…
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, Founder at SQUR.
MITRE CAPEC attack patterns — by abstraction | SQUR Knowledge Base