Compliance Node Overview
MITRE CAPEC-633 (Token Impersonation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then associates a process/thread to that that impersonated token. This action causes a downstream user to make a decision or take action that is based on the assumed identity, and not the response that blocks the adversary. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-287, CWE-1270. Relates to MITRE ATT&CK T1134.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/633.html
SHA-256 integrity: c9363d2a2213bc11549cde6d7c1cc1dac86d60b9a4c3f8d896d622d883aaaad2
Primary Citations — 10 traced to source
- MITRE CAPEC-633: Token Impersonation (https://capec.mitre.org/data/definitions/633.html)
- CWE-287: underlying weakness (http://cwe.mitre.org/data/definitions/287.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.