{
  "node_id": "mitre-capec-capec-545-pull-data-from-system-resources",
  "title": "MITRE CAPEC-545: Pull Data from System Resources (Standard Attack Pattern)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-545 (Pull Data from System Resources) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary who is authorized or has the ability to search known system resources, does so with the intention of gathering useful information. System resources include files, memory, and other aspects of the target system. In this pattern of attack, the adversary does not necessarily know what they are going to find when they start pulling data. Likelihood of attack: Unknown. Parent pattern for CAPEC-498 Probe iOS Screenshots; CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment; CAPEC-634 Probe Audio and Video Peripherals; and others. Maps to weaknesses CWE-1239, CWE-1243, CWE-1258, CWE-1266, and others. Relates to MITRE ATT&CK T1005, T1555.001.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2",
    "mitre-attack-t1005-data-from-local-system",
    "mitre-attack-t1555-credentials-from-password-stores"
  ],
  "primary_citations_count": 13
}