Compliance Node Overview
MITRE CAPEC-302 (TCP FIN Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a TCP FIN scan to determine if ports are closed on the target machine. This scan type is accomplished by sending TCP segments with the FIN bit set in the packet header. The RFC 793 expected behavior is that any TCP segment with an out-of-state Flag sent to an open port is discarded, whereas segments with out-of-state flags sent to closed ports should be handled with a RST in response. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/302.html
SHA-256 integrity: 2353966329823d8ee8239f74118818fe2152eab451d93eab2a1b419159839488
Primary Citations — 7 traced to source
- MITRE CAPEC-302: TCP FIN Scan (https://capec.mitre.org/data/definitions/302.html)
- CWE-200: underlying weakness (http://cwe.mitre.org/data/definitions/200.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.