What MITRE CAPEC-558: Replace Trusted Executable (Detailed Attack Pattern - High Severity) requires
MITRE CAPEC-558 (Replace Trusted Executable) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits weaknesses in privilege management or access control to replace a trusted executable with a malicious version and enable the execution of malware when that trusted executable is called. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1505.005, T1546.008.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/558.html
SHA-256 integrity: 991687b26f432c6d1c254031fb96414226aaf19aa9e7574c47a92d335af0226c
Primary Citations — 10 traced to source
- MITRE CAPEC-558: Replace Trusted Executable (https://capec.mitre.org/data/definitions/558.html)
- CWE-284: underlying weakness (http://cwe.mitre.org/data/definitions/284.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-capec-capec-558-replace-trusted-executable.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-capec-capec-558-replace-trusted-executable.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-capec-capec-558-replace-trusted-executable
- Back to registry: Browse all 10,085 compliance nodes