Compliance Node Overview
MITRE CAPEC-150 (Collect Data from Common Resource Locations) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits well-known locations for resources for the purposes of undermining the security of the target. In many, if not most systems, files and resources are organized in a default tree structure. This can be useful for adversaries because they often know where to look for resources or files that are necessary for attacks. Likelihood of attack: Unknown. Typical severity: Medium. Parent pattern for CAPEC-143 Detect Unpublicized Web Pages; CAPEC-144 Detect Unpublicized Web Services; CAPEC-155 Screen Temporary Files for Sensitive Information; and others. Maps to weaknesses CWE-552, CWE-1239, CWE-1258, CWE-1266, and others. Relates to MITRE ATT&CK T1003, T1119, T1213.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/150.html
SHA-256 integrity: 1e1b9775b7cf5cf959052c746172b0d718e0a8ee9fb647e9e07a7107fb66e462
Primary Citations — 13 traced to source
- MITRE CAPEC-150: Collect Data from Common Resource Locations (https://capec.mitre.org/data/definitions/150.html)
- CWE-552: underlying weakness (http://cwe.mitre.org/data/definitions/552.html)
+ 11 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.