Compliance Node Overview
MITRE CAPEC-326 (TCP Initial Window Size Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe checks the initial TCP Window size. TCP stacks limit the range of sequence numbers allowable within a session to maintain the "connected" state within TCP protocol logic. The initial window size specifies a range of acceptable sequence numbers that will qualify as a response to an ACK packet within a session. Various operating systems use different Initial window sizes. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/326.html
SHA-256 integrity: 6830b39f2b0c81f1de45db9e629612a5c4ab14f16442c91e715f1ba2bcade09a
Primary Citations — 7 traced to source
- MITRE CAPEC-326: TCP Initial Window Size Probe (https://capec.mitre.org/data/definitions/326.html)
- CWE-200: underlying weakness (http://cwe.mitre.org/data/definitions/200.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.