Compliance Node Overview
MITRE CAPEC-636 (Hiding Malicious Data or Code within Files) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Files on various operating systems can have a complex format which allows for the storage of other data, in addition to its contents. Often this is metadata about the file, such as a cached thumbnail for an image file. Unless utilities are invoked in a particular way, this data is not visible during the normal use of the file. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-168 Windows ::DATA Alternate Data Stream; CAPEC-35 Leverage Executable Code in Non-Executable Files. Maps to weaknesses CWE-506. Relates to MITRE ATT&CK T1001.002, T1027.003, T1027.004.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/636.html
SHA-256 integrity: 2864336515c8311d1835f477f99a70ea3d06350fd356292c96080828a1a7128e
Primary Citations — 10 traced to source
- MITRE CAPEC-636: Hiding Malicious Data or Code within Files (https://capec.mitre.org/data/definitions/636.html)
- CWE-506: underlying weakness (http://cwe.mitre.org/data/definitions/506.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.