{
  "node_id": "mitre-capec-capec-635-alternative-execution-due-to-deceptive-filenames",
  "title": "MITRE CAPEC-635: Alternative Execution Due to Deceptive Filenames (Standard Attack Pattern - High Severity)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-635 (Alternative Execution Due to Deceptive Filenames) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The extension of a file name is often used in various contexts to determine the application that is used to open and use it. If an attacker can cause an alternative application to be used, it may be able to execute malicious code, cause a denial of service or expose sensitive information. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-11 Cause Web Server Misclassification; CAPEC-649 Adding a Space to a File Extension. Maps to weaknesses CWE-162. Relates to MITRE ATT&CK T1036.007.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2",
    "mitre-attack-t1036-masquerading"
  ],
  "primary_citations_count": 9
}