What MITRE CAPEC-321: TCP Sequence Number Probe (Detailed Attack Pattern - Low Severity) requires
MITRE CAPEC-321 (TCP Sequence Number Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests the target system's assignment of TCP sequence numbers. One common way to test TCP Sequence Number generation is to send a probe packet to an open port on the target and then compare the how the Sequence Number generated by the target relates to the Acknowledgement Number in the probe packet. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/321.html
SHA-256 integrity: 3b99aab054f90d7f4c1b8b674e4014e892b7e2855f55c1b495134814d7f1d5c7
Primary Citations — 7 traced to source
- MITRE CAPEC-321: TCP Sequence Number Probe (https://capec.mitre.org/data/definitions/321.html)
- CWE-200: underlying weakness (http://cwe.mitre.org/data/definitions/200.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-capec-capec-321-tcp-sequence-number-probe.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-capec-capec-321-tcp-sequence-number-probe.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-capec-capec-321-tcp-sequence-number-probe
- Back to registry: Browse all 10,085 compliance nodes