{
  "node_id": "mitre-capec-capec-555-remote-services-with-stolen-credentials",
  "title": "MITRE CAPEC-555: Remote Services with Stolen Credentials (Standard Attack Pattern - Very High Severity)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-555 (Remote Services with Stolen Credentials) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack involves an adversary that uses stolen credentials to leverage remote services such as RDP, telnet, SSH, and VNC to log into a system. Once access is gained, any number of malicious activities could be performed. Likelihood of attack: Unknown. Typical severity: Very High. Maps to weaknesses CWE-522, CWE-308, CWE-309, CWE-294, and others. Relates to MITRE ATT&CK T1021, T1114.002, T1133.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2",
    "mitre-attack-t1021-008-direct-cloud-vm-connections",
    "mitre-attack-t1114-003-email-forwarding-rule"
  ],
  "primary_citations_count": 13
}