Compliance Node Overview
MITRE CAPEC-392 (Lock Bumping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses a bump key to force a lock on a building or facility and gain entry. Lock Bumping is the use of a special type of key that can be tapped or bumped to cause the pins within the lock to fall into temporary alignment, allowing the lock to be opened. Lock bumping allows an attacker to open a lock without having the correct key. A standard lock is secured by a set of internal pins that prevent the device from turning. Spring loaded driver pins push down on the key pins. When the correct key is inserted, the ridges on the key push the key pins up and against the driver pins, causing correct alignment which allows the lock cylinder to rotate. A bump key is a specially constructed key that exploits this design. When the bump key is struck or firmly tapped, its teeth transfer the force of the tap into the key pins, causing the lock to momentarily shift into proper alignment for the mechanism to be opened. Child of CAPEC-391.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/392.html
SHA-256 integrity: 0f7f5cea0c857b8c38216d9faf481223996910efe3922bd8b757ba9c920ac65a
Primary Citations — 8 traced to source
- MITRE CAPEC-392: Lock Bumping (https://capec.mitre.org/data/definitions/392.html)
- MITRE Common Attack Pattern Enumeration and Classification (CAPEC) (https://capec.mitre.org/)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.