Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE CAPEC-320: TCP Timestamp Probe (Detailed Attack Pattern - Low Severity)

MITRE CAPEC-320 (TCP Timestamp Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS…

What MITRE CAPEC-320: TCP Timestamp Probe (Detailed Attack Pattern - Low Severity) requires

MITRE CAPEC-320 (TCP Timestamp Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe examines the remote server's implementation of TCP timestamps. Not all operating systems implement timestamps within the TCP header, but when timestamps are used then this provides the attacker with a means to guess the operating system of the target. The attacker begins by probing any active TCP service in order to get response which contains a TCP timestamp. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://capec.mitre.org/data/definitions/320.html

SHA-256 integrity: f1b1e19607731d3f5a5119b192638d087284ba075162c523265d47346b0632b7

Primary Citations — 7 traced to source

  • MITRE CAPEC-320: TCP Timestamp Probe (https://capec.mitre.org/data/definitions/320.html)
  • CWE-200: underlying weakness (http://cwe.mitre.org/data/definitions/200.html)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.