Nodes:
CAPEC-1 - MITRE CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs (Standard Attack Pattern - High Severity)
MITRE CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In applications, particularly web applications, access to functionality is mitigated by an authorization
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-1-accessing-functionality-not-properly-constrained-by-acls
CAPEC-2 - MITRE CAPEC-2: Inducing Account Lockout (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-2 (Inducing Account Lockout) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages the security functionality of the system aimed at thwarting potential attacks to launch a denial of service attack
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-2-inducing-account-lockout
CAPEC-3 - MITRE CAPEC-3: Using Leading 'Ghost' Character Sequences to Bypass Input Filters (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-3 (Using Leading 'Ghost' Character Sequences to Bypass Input Filters) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some APIs will strip certain leading characters from a string of parameters. An adversary can in
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-3-using-leading-ghost-character-sequences-to-bypass-input
CAPEC-4 - MITRE CAPEC-4: Using Alternative IP Address Encodings (Detailed Attack Pattern - High Severity)
MITRE CAPEC-4 (Using Alternative IP Address Encodings) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack relies on the adversary using unexpected formats for representing IP addresses. Networked applications may expe
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-4-using-alternative-ip-address-encodings
CAPEC-5 - MITRE CAPEC-5: Blue Boxing (Detailed Attack Pattern - Very High Severity; DEPRECATED by MITRE, retained as a historical record)
MITRE CAPEC-5 (Blue Boxing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack against older telephone switches and trunks has been around for decades. A tone is sent by an adversary to impersonate a superviso
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-5-blue-boxing
CAPEC-6 - MITRE CAPEC-6: Argument Injection (Standard Attack Pattern - High Severity)
MITRE CAPEC-6 (Argument Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker changes the behavior or state of a targeted application through injecting data or command syntax through the targets use of non-val
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-6-argument-injection
CAPEC-7 - MITRE CAPEC-7: Blind SQL Injection (Detailed Attack Pattern - High Severity)
MITRE CAPEC-7 (Blind SQL Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Blind SQL Injection results from an insufficient mitigation for SQL Injection. Although suppressing database error messages are considered bes
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-7-blind-sql-injection
CAPEC-8 - MITRE CAPEC-8: Buffer Overflow in an API Call (Detailed Attack Pattern - High Severity)
MITRE CAPEC-8 (Buffer Overflow in an API Call) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets libraries or shared code modules which are vulnerable to buffer overflow attacks. An adversary who has knowledg
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-8-buffer-overflow-in-an-api-call
CAPEC-9 - MITRE CAPEC-9: Buffer Overflow in Local Command-Line Utilities (Detailed Attack Pattern - High Severity)
MITRE CAPEC-9 (Buffer Overflow in Local Command-Line Utilities) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets command-line utilities available in a number of shells. An adversary can leverage a vulnerabil
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-9-buffer-overflow-in-local-command-line-utilities
CAPEC-10 - MITRE CAPEC-10: Buffer Overflow via Environment Variables (Detailed Attack Pattern - High Severity)
MITRE CAPEC-10 (Buffer Overflow via Environment Variables) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the adversar
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-10-buffer-overflow-via-environment-variables
CAPEC-11 - MITRE CAPEC-11: Cause Web Server Misclassification (Detailed Attack Pattern - High Severity)
MITRE CAPEC-11 (Cause Web Server Misclassification) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a Web server's decision to take action based on filename or file extension. Because different
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-11-cause-web-server-misclassification
CAPEC-12 - MITRE CAPEC-12: Choosing Message Identifier (Standard Attack Pattern - High Severity)
MITRE CAPEC-12 (Choosing Message Identifier) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack is defined by the selection of messages distributed via multicast or public information channels that are inte
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-12-choosing-message-identifier
CAPEC-13 - MITRE CAPEC-13: Subverting Environment Variable Values (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-13 (Subverting Environment Variable Values) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary directly or indirectly modifies environment variables used by or controlling the target software. The advers
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-13-subverting-environment-variable-values
CAPEC-14 - MITRE CAPEC-14: Client-side Injection-induced Buffer Overflow (Detailed Attack Pattern - High Severity)
MITRE CAPEC-14 (Client-side Injection-induced Buffer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack exploits a buffer overflow vulnerability in targeted client software through injection of malic
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-14-client-side-injection-induced-buffer-overflow
CAPEC-15 - MITRE CAPEC-15: Command Delimiters (Standard Attack Pattern - High Severity)
MITRE CAPEC-15 (Command Delimiters) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a programs' vulnerabilities that allows an attacker's commands to be concatenated onto a legitimate command wi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-15-command-delimiters
CAPEC-16 - MITRE CAPEC-16: Dictionary-based Password Attack (Detailed Attack Pattern - High Severity)
MITRE CAPEC-16 (Dictionary-based Password Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker tries each of the words in a dictionary as passwords to gain access to the system via some user's account. If the pa
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-16-dictionary-based-password-attack
CAPEC-17 - MITRE CAPEC-17: Using Malicious Files (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-17 (Using Malicious Files) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a system's configuration that allows an adversary to either directly access an executable file, for example
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-17-using-malicious-files
CAPEC-18 - MITRE CAPEC-18: XSS Targeting Non-Script Elements (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-18 (XSS Targeting Non-Script Elements) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack is a form of Cross-Site Scripting (XSS) where malicious scripts are embedded in elements that are not expected to h
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-18-xss-targeting-non-script-elements
CAPEC-19 - MITRE CAPEC-19: Embedding Scripts within Scripts (Standard Attack Pattern - High Severity)
MITRE CAPEC-19 (Embedding Scripts within Scripts) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages the capability to execute their own script by embedding it within other scripts that the target software
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-19-embedding-scripts-within-scripts
CAPEC-20 - MITRE CAPEC-20: Encryption Brute Forcing (Standard Attack Pattern - Low Severity)
MITRE CAPEC-20 (Encryption Brute Forcing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker, armed with the cipher text and the encryption algorithm used, performs an exhaustive (brute force) search on the key space
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-20-encryption-brute-forcing
CAPEC-21 - MITRE CAPEC-21: Exploitation of Trusted Identifiers (Attack Pattern - High Severity)
MITRE CAPEC-21 (Exploitation of Trusted Identifiers) is an attack pattern in which an adversary manipulates trusted identifiers (session IDs, cookies, access tokens, SAML assertions, OAuth tokens) to impersonate authenticated users. Prerequisites: weak identifier proof/verificati
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-21-exploitation-of-trusted-identifiers
CAPEC-22 - MITRE CAPEC-22: Exploiting Trust in Client (Attack Pattern - High Severity)
MITRE CAPEC-22 (Exploiting Trust in Client) is an attack pattern in which an attacker communicates directly with the server where the server believes it is communicating only with a valid client. Likelihood: High. Severity: High. Maps to CWE-290 (Authentication Bypass by Spoofing
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-22-exploiting-trust-in-client
CAPEC-23 - MITRE CAPEC-23: File Content Injection (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-23 (File Content Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary poisons files with a malicious payload (targeting the file systems accessible by the target software), which may be passed th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-23-file-content-injection
CAPEC-24 - MITRE CAPEC-24: Filter Failure through Buffer Overflow (Detailed Attack Pattern - High Severity)
MITRE CAPEC-24 (Filter Failure through Buffer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-24-filter-failure-through-buffer-overflow
CAPEC-25 - MITRE CAPEC-25: Forced Deadlock (Meta Attack Pattern - High Severity)
MITRE CAPEC-25 (Forced Deadlock) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary triggers and exploits a deadlock condition in the target software to cause a denial of service. A deadlock can occur when two or more c
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-25-forced-deadlock
CAPEC-26 - MITRE CAPEC-26: Leveraging Race Conditions (Meta Attack Pattern - High Severity)
MITRE CAPEC-26 (Leveraging Race Conditions) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary targets a race condition occurring when multiple processes access and manipulate the same resource concurrently, and the out
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-26-leveraging-race-conditions
CAPEC-27 - MITRE CAPEC-27: Leveraging Race Conditions via Symbolic Links (Detailed Attack Pattern - High Severity)
MITRE CAPEC-27 (Leveraging Race Conditions via Symbolic Links) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack leverages the use of symbolic links (Symlinks) in order to write to sensitive files. An attacker can cr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-27-leveraging-race-conditions-via-symbolic-links
CAPEC-28 - MITRE CAPEC-28: Fuzzing (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-28 (Fuzzing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary leverages fuzzing to try to identify weaknesses in the system. Fuzzing is a software security and functionality testing
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-28-fuzzing
CAPEC-29 - MITRE CAPEC-29: Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions (Standard Attack Pattern - High Severity)
MITRE CAPEC-29 (Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets a race condition occurring between the time of check (state) for a resource
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-29-leveraging-time-of-check-and-time-of-use
CAPEC-30 - MITRE CAPEC-30: Hijacking a Privileged Thread of Execution (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-30 (Hijacking a Privileged Thread of Execution) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary hijacks a privileged thread of execution by injecting malicious code into a running process. By using a p
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-30-hijacking-a-privileged-thread-of-execution
CAPEC-31 - MITRE CAPEC-31: Accessing/Intercepting/Modifying HTTP Cookies (Attack Pattern - High Severity)
MITRE CAPEC-31 (Accessing/Intercepting/Modifying HTTP Cookies) is an attack pattern that exploits HTTP cookies in three ways: accessing cookies to extract sensitive data, intercepting transmitted cookies for impersonation, or modifying cookie content. Relies on cookies storing cr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-31-http-cookies
CAPEC-32 - MITRE CAPEC-32: XSS Through HTTP Query Strings (Detailed Attack Pattern - High Severity)
MITRE CAPEC-32 (XSS Through HTTP Query Strings) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary embeds malicious script code in the parameters of an HTTP query string and convinces a victim to submit the HTTP requ
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-32-xss-through-http-query-strings
CAPEC-33 - MITRE CAPEC-33: HTTP Request Smuggling (Detailed Attack Pattern - High Severity)
MITRE CAPEC-33 (HTTP Request Smuggling) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages using various HTTP header
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-33-http-request-smuggling
CAPEC-34 - MITRE CAPEC-34: HTTP Response Splitting (Detailed Attack Pattern - High Severity)
MITRE CAPEC-34 (HTTP Response Splitting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates and injects malicious content, in the form of secret unauthorized HTTP responses, into a single HTTP response fr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-34-http-response-splitting
CAPEC-35 - MITRE CAPEC-35: Leverage Executable Code in Non-Executable Files (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-35 (Leverage Executable Code in Non-Executable Files) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a system's trust in configuration and resource files. When the executable loads
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-35-leverage-executable-code-in-non-executable-files
CAPEC-36 - MITRE CAPEC-36: Using Unpublished Interfaces or Functionality (Standard Attack Pattern - High Severity)
MITRE CAPEC-36 (Using Unpublished Interfaces or Functionality) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary searches for and invokes interfaces or functionality that the target system designers did not intend t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-36-using-unpublished-interfaces-or-functionality
CAPEC-37 - MITRE CAPEC-37: Retrieve Embedded Sensitive Data (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-37 (Retrieve Embedded Sensitive Data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker examines a target system to find sensitive data that has been embedded within it. This information can reveal confid
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-37-retrieve-embedded-sensitive-data
CAPEC-38 - MITRE CAPEC-38: Leveraging/Manipulating Configuration File Search Paths (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack sees an adversary load a malicious resource into a program's standard path so that
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-38-leveraging-manipulating-configuration-file-search-paths
CAPEC-39 - MITRE CAPEC-39: Manipulating Opaque Client-based Data Tokens (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-39 (Manipulating Opaque Client-based Data Tokens) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In circumstances where an application holds important data client-side in tokens (cookies, URLs, data files, and so
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-39-manipulating-opaque-client-based-data-tokens
CAPEC-40 - MITRE CAPEC-40: Manipulating Writeable Terminal Devices (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-40 (Manipulating Writeable Terminal Devices) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack exploits terminal devices that allow themselves to be written to by other users. The attacker sends command s
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-40-manipulating-writeable-terminal-devices
CAPEC-41 - MITRE CAPEC-41: Using Meta-characters in E-mail Headers to Inject Malicious Payloads (Detailed Attack Pattern - High Severity)
MITRE CAPEC-41 (Using Meta-characters in E-mail Headers to Inject Malicious Payloads) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack involves an attacker leveraging meta-characters in email headers to inje
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-41-using-meta-characters-in-e-mail-headers-to
CAPEC-42 - MITRE CAPEC-42: MIME Conversion (Detailed Attack Pattern - High Severity)
MITRE CAPEC-42 (MIME Conversion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the mail server machine. The MIME
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-42-mime-conversion
CAPEC-43 - MITRE CAPEC-43: Exploiting Multiple Input Interpretation Layers (Detailed Attack Pattern - High Severity)
MITRE CAPEC-43 (Exploiting Multiple Input Interpretation Layers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker supplies the target software with input data that contains sequences of special characters designed t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-43-exploiting-multiple-input-interpretation-layers
CAPEC-44 - MITRE CAPEC-44: Overflow Binary Resource File (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-44 (Overflow Binary Resource File) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a buffer overflow vulnerability in the handling of binary resources. Binary resources may include m
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-44-overflow-binary-resource-file
CAPEC-45 - MITRE CAPEC-45: Buffer Overflow via Symbolic Links (Detailed Attack Pattern - High Severity)
MITRE CAPEC-45 (Buffer Overflow via Symbolic Links) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-45-buffer-overflow-via-symbolic-links
CAPEC-46 - MITRE CAPEC-46: Overflow Variables and Tags (Detailed Attack Pattern - High Severity)
MITRE CAPEC-46 (Overflow Variables and Tags) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack leverages the use of tags or variables from a formatted configuration data to cause buffer overflow. The adversar
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-46-overflow-variables-and-tags
CAPEC-47 - MITRE CAPEC-47: Buffer Overflow via Parameter Expansion (Detailed Attack Pattern - High Severity)
MITRE CAPEC-47 (Buffer Overflow via Parameter Expansion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack, the target software is given input that the adversary knows will be modified and expanded in size during
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-47-buffer-overflow-via-parameter-expansion
CAPEC-48 - MITRE CAPEC-48: Passing Local Filenames to Functions That Expect a URL (Standard Attack Pattern - High Severity)
MITRE CAPEC-48 (Passing Local Filenames to Functions That Expect a URL) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack relies on client side code to access local files and resources instead of URLs. When the clien
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-48-passing-local-filenames-to-functions-that-expect-a
CAPEC-49 - MITRE CAPEC-49: Password Brute Forcing (Attack Pattern - High Severity)
MITRE CAPEC-49 (Password Brute Forcing) is an attack pattern in which an adversary tries every possible value for a password until they succeed. The CAPEC page identifies three prerequisites: adversary needs username; system uses password-based single-factor authentication; appli
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-49-password-brute-forcing
CAPEC-50 - MITRE CAPEC-50: Password Recovery Exploitation (Standard Attack Pattern - High Severity)
MITRE CAPEC-50 (Password Recovery Exploitation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may take advantage of the application feature to help users recover their forgotten passwords in order to gain access
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-50-password-recovery-exploitation
CAPEC-51 - MITRE CAPEC-51: Poison Web Service Registry (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-51 (Poison Web Service Registry) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A poisoned registr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-51-poison-web-service-registry
CAPEC-52 - MITRE CAPEC-52: Embedding NULL Bytes (Detailed Attack Pattern - High Severity)
MITRE CAPEC-52 (Embedding NULL Bytes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary embeds one or more null bytes in input to the target software. This attack relies on the usage of a null-valued byte as a strin
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-52-embedding-null-bytes
CAPEC-53 - MITRE CAPEC-53: Postfix, Null Terminate, and Backslash (Detailed Attack Pattern - High Severity)
MITRE CAPEC-53 (Postfix, Null Terminate, and Backslash) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. If a string is passed through a filter of some kind, then a terminal NULL may not be valid. Using alternate representation
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-53-postfix-null-terminate-and-backslash
CAPEC-54 - MITRE CAPEC-54: Query System for Information (Standard Attack Pattern - Low Severity)
MITRE CAPEC-54 (Query System for Information) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, aware of an application's location (and possibly authorized to use the application), probes an application's structure
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-54-query-system-for-information
CAPEC-55 - MITRE CAPEC-55: Rainbow Table Password Cracking (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-55 (Rainbow Table Password Cracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker gets access to the database table where hashes of passwords are stored. They then use a rainbow table of pre-computed
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-55-rainbow-table-password-cracking
CAPEC-57 - MITRE CAPEC-57: Utilizing REST's Trust in the System Resource to Obtain Sensitive Data (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-57 (Utilizing REST's Trust in the System Resource to Obtain Sensitive Data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-57-utilizing-rest-s-trust-in-the-system-resource
CAPEC-58 - MITRE CAPEC-58: Restful Privilege Elevation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-58 (Restful Privilege Elevation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary identifies a Rest HTTP (Get, Put, Delete) style permission method allowing them to perform various malicious actions upo
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-58-restful-privilege-elevation
CAPEC-59 - MITRE CAPEC-59: Session Credential Falsification through Prediction (Detailed Attack Pattern - High Severity)
MITRE CAPEC-59 (Session Credential Falsification through Prediction) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets predictable session ID in order to gain privileges. The attacker can predict the session
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-59-session-credential-falsification-through-prediction
CAPEC-60 - MITRE CAPEC-60: Reusing Session IDs (aka Session Replay) (Detailed Attack Pattern - High Severity)
MITRE CAPEC-60 (Reusing Session IDs (aka Session Replay)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The attacker t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-60-reusing-session-ids-aka-session-replay
CAPEC-61 - MITRE CAPEC-61: Session Fixation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-61 (Session Fixation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker induces a client to establish a session with the target software using a session identifier provided by the attacker. Once the user
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-61-session-fixation
CAPEC-62 - MITRE CAPEC-62: Cross-Site Request Forgery (CSRF) (Attack Pattern - Very High Severity)
MITRE CAPEC-62 (Cross-Site Request Forgery) is an attack pattern in which an attacker crafts malicious web links to induce users to click and execute malicious actions against third-party applications. Leverages session cookies persisting after authentication. Likelihood: High. S
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-62-cross-site-request-forgery
CAPEC-63 - MITRE CAPEC-63: Cross-Site Scripting (XSS) (Attack Pattern - Very High Severity)
MITRE CAPEC-63 (Cross-Site Scripting) is an attack pattern in which an adversary embeds malicious scripts in content that will be served to web browsers; the target client-side browser executes the script with the users privilege level. Likelihood of attack: High. Typical severit
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-63-cross-site-scripting
CAPEC-64 - MITRE CAPEC-64: Using Slashes and URL Encoding Combined to Bypass Validation Logic (Detailed Attack Pattern - High Severity)
MITRE CAPEC-64 (Using Slashes and URL Encoding Combined to Bypass Validation Logic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the encoding of the URL combined with the encoding of the slash characters
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-64-using-slashes-and-url-encoding-combined-to-bypass
CAPEC-65 - MITRE CAPEC-65: Sniff Application Code (Detailed Attack Pattern - High Severity)
MITRE CAPEC-65 (Sniff Application Code) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary passively sniffs network communications and captures application code bound for an authorized client. Once obtained, they can
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-65-sniff-application-code
CAPEC-66 - MITRE CAPEC-66: SQL Injection (Attack Pattern - High Severity)
MITRE CAPEC-66 (SQL Injection) is an attack pattern in which an adversary crafts input strings so that the target software constructs SQL statements that perform actions other than those intended by the application. Likelihood of attack: High. Typical severity: High. Maps to CWE-
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-66-sql-injection
CAPEC-67 - MITRE CAPEC-67: String Format Overflow in syslog() (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-67 (String Format Overflow in syslog()) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets applications and software that uses the syslog() function insecurely. If an application does not explicite
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-67-string-format-overflow-in-syslog
CAPEC-68 - MITRE CAPEC-68: Subvert Code-signing Facilities (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-68 (Subvert Code-signing Facilities) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Many languages use code signing facilities to vouch for code's identity and to thus tie code to its assigned privileges within an
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-68-subvert-code-signing-facilities
CAPEC-69 - MITRE CAPEC-69: Target Programs with Elevated Privileges (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-69 (Target Programs with Elevated Privileges) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets programs running with elevated privileges. The adversary tries to leverage a vulnerability in the ru
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-69-target-programs-with-elevated-privileges
CAPEC-70 - MITRE CAPEC-70: Try Common or Default Usernames and Passwords (Detailed Attack Pattern - High Severity)
MITRE CAPEC-70 (Try Common or Default Usernames and Passwords) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may try certain common or default usernames and passwords to gain access into the system and perform u
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-70-try-common-or-default-usernames-and-passwords
CAPEC-71 - MITRE CAPEC-71: Using Unicode Encoding to Bypass Validation Logic (Detailed Attack Pattern - High Severity)
MITRE CAPEC-71 (Using Unicode Encoding to Bypass Validation Logic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may provide a Unicode string to a system component that is not Unicode aware and use that to circum
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-71-using-unicode-encoding-to-bypass-validation-logic
CAPEC-72 - MITRE CAPEC-72: URL Encoding (Detailed Attack Pattern - High Severity)
MITRE CAPEC-72 (URL Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the encoding of the URL. An adversary can take advantage of the multiple way of encoding an URL and abuse the interpretation of
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-72-url-encoding
CAPEC-73 - MITRE CAPEC-73: User-Controlled Filename (Standard Attack Pattern - High Severity)
MITRE CAPEC-73 (User-Controlled Filename) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type involves an adversary inserting malicious characters (such as a XSS redirection) into a filename, directly or ind
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-73-user-controlled-filename
CAPEC-74 - MITRE CAPEC-74: Manipulating State (Meta Attack Pattern - High Severity)
MITRE CAPEC-74 (Manipulating State) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary modifies state information maintained by the target software or causes a state transition in hardware. If successful, the target wil
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-74-manipulating-state
CAPEC-75 - MITRE CAPEC-75: Manipulating Writeable Configuration Files (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-75 (Manipulating Writeable Configuration Files) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Generally these are manually edited files that are not in the preview of the system administrators, any ability on the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-75-manipulating-writeable-configuration-files
CAPEC-76 - MITRE CAPEC-76: Manipulating Web Input to File System Calls (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-76 (Manipulating Web Input to File System Calls) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates inputs to the target software which the target software passes to file system calls in the OS
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-76-manipulating-web-input-to-file-system-calls
CAPEC-77 - MITRE CAPEC-77: Manipulating User-Controlled Variables (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-77 (Manipulating User-Controlled Variables) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets user controlled variables (DEBUG=1, PHP Globals, and So Forth). An adversary can override variables le
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-77-manipulating-user-controlled-variables
CAPEC-78 - MITRE CAPEC-78: Using Escaped Slashes in Alternate Encoding (Detailed Attack Pattern - High Severity)
MITRE CAPEC-78 (Using Escaped Slashes in Alternate Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the use of the backslash in alternate encoding. An adversary can provide a backslash as a leading
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-78-using-escaped-slashes-in-alternate-encoding
CAPEC-79 - MITRE CAPEC-79: Using Slashes in Alternate Encoding (Detailed Attack Pattern - High Severity)
MITRE CAPEC-79 (Using Slashes in Alternate Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the encoding of the Slash characters. An adversary would try to exploit common filtering problems related
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-79-using-slashes-in-alternate-encoding
CAPEC-80 - MITRE CAPEC-80: Using UTF-8 Encoding to Bypass Validation Logic (Detailed Attack Pattern - High Severity)
MITRE CAPEC-80 (Using UTF-8 Encoding to Bypass Validation Logic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack is a specific variation on leveraging alternate encodings to bypass validation logic. This attack lev
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-80-using-utf-8-encoding-to-bypass-validation-logic
CAPEC-81 - MITRE CAPEC-81: Web Server Logs Tampering (Detailed Attack Pattern - High Severity)
MITRE CAPEC-81 (Web Server Logs Tampering) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Web Logs Tampering attacks involve an attacker injecting, deleting or otherwise tampering with the contents of web logs typically for t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-81-web-server-logs-tampering
CAPEC-83 - MITRE CAPEC-83: XPath Injection (Detailed Attack Pattern - High Severity)
MITRE CAPEC-83 (XPath Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker can craft special user-controllable input consisting of XPath expressions to inject the XML database and bypass authentication or gle
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-83-xpath-injection
CAPEC-84 - MITRE CAPEC-84: XQuery Injection (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-84 (XQuery Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack utilizes XQuery to probe and attack server systems; in a similar manner that SQL Injection allows an attacker to exploit SQL calls t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-84-xquery-injection
CAPEC-85 - MITRE CAPEC-85: AJAX Footprinting (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-85 (AJAX Footprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabiliti
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-85-ajax-footprinting
CAPEC-86 - MITRE CAPEC-86: XSS Through HTTP Headers (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-86 (XSS Through HTTP Headers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits web applications that generate web content, such as links in a HTML page, based on unvalidated or improperly valid
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-86-xss-through-http-headers
CAPEC-87 - MITRE CAPEC-87: Forceful Browsing (Standard Attack Pattern - High Severity)
MITRE CAPEC-87 (Forceful Browsing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker employs forceful browsing (direct URL entry) to access portions of a website that are otherwise unreachable. Usually, a front contr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-87-forceful-browsing
CAPEC-88 - MITRE CAPEC-88: OS Command Injection (Attack Pattern - High Severity)
MITRE CAPEC-88 (OS Command Injection) is an attack pattern in which an adversary injects operating system commands into existing application functions. Applications using untrusted input to build command strings are vulnerable. Likelihood: High. Severity: High. Maps to CWE-78 (OS
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-88-os-command-injection
CAPEC-89 - MITRE CAPEC-89: Pharming (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-89 (Pharming) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A pharming attack occurs when the victim is fooled into entering sensitive data into supposedly trusted locations, such as an online bank site or a trad
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-89-pharming
CAPEC-90 - MITRE CAPEC-90: Reflection Attack in Authentication Protocol (Standard Attack Pattern - High Severity)
MITRE CAPEC-90 (Reflection Attack in Authentication Protocol) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary can abuse an authentication protocol susceptible to reflection attack in order to defeat it. Doing so a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-90-reflection-attack-in-authentication-protocol
CAPEC-92 - MITRE CAPEC-92: Forced Integer Overflow (Detailed Attack Pattern - High Severity)
MITRE CAPEC-92 (Forced Integer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack forces an integer variable to go out of range. The integer variable is often used as an offset such as size of memory allocat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-92-forced-integer-overflow
CAPEC-93 - MITRE CAPEC-93: Log Injection-Tampering-Forging (Detailed Attack Pattern - High Severity)
MITRE CAPEC-93 (Log Injection-Tampering-Forging) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the log files of the target host. The attacker injects, manipulates or forges malicious log entries in the lo
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-93-log-injection-tampering-forging
CAPEC-94 - MITRE CAPEC-94: Adversary in the Middle (AiTM) (Attack Pattern - Very High Severity)
MITRE CAPEC-94 (Adversary in the Middle) is an attack pattern in which an adversary targets the communication between two components (typically client and server) to alter or obtain data from transactions. Likelihood of attack: High. Typical severity: Very High. Maps to MITRE ATT
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-94-adversary-in-the-middle
CAPEC-95 - MITRE CAPEC-95: WSDL Scanning (Detailed Attack Pattern - High Severity)
MITRE CAPEC-95 (WSDL Scanning) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack targets the WSDL interface made available by a web service. The attacker may scan the WSDL interface to reveal sensitive information ab
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-95-wsdl-scanning
CAPEC-96 - MITRE CAPEC-96: Block Access to Libraries (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-96 (Block Access to Libraries) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An application typically makes calls to functions that are a part of libraries external to the application. These libraries may be part
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-96-block-access-to-libraries
CAPEC-97 - MITRE CAPEC-97: Cryptanalysis (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-97 (Cryptanalysis) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Cryptanalysis is a process of finding weaknesses in cryptographic algorithms and using these weaknesses to decipher the ciphertext without knowing
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-97-cryptanalysis
CAPEC-98 - MITRE CAPEC-98: Phishing (Attack Pattern - Very High Severity)
MITRE CAPEC-98 (Phishing) is a social engineering attack pattern in which an attacker masquerades as a legitimate entity to prompt the user to reveal confidential information (very frequently authentication credentials). Likelihood of attack: High. Typical severity: Very High. Ma
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-98-phishing
CAPEC-100 - MITRE CAPEC-100: Overflow Buffers (Buffer Overflow Attacks) (Very High Severity)
MITRE CAPEC-100 (Overflow Buffers) targets improper or missing bounds checking on buffer operations, typically triggered by attacker-injected input. Results in program crash or unauthorized code execution. Likelihood: High. Severity: Very High. Maps to CWE-120 (Classic Buffer Ove
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-100-buffer-overflow
CAPEC-101 - MITRE CAPEC-101: Server Side Include (SSI) Injection (Detailed Attack Pattern - High Severity)
MITRE CAPEC-101 (Server Side Include (SSI) Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker can use Server Side Include (SSI) Injection to send code to a web application that then gets executed by the web
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-101-server-side-include-ssi-injection
CAPEC-102 - MITRE CAPEC-102: Session Sidejacking (Detailed Attack Pattern - High Severity)
MITRE CAPEC-102 (Session Sidejacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Session sidejacking takes advantage of an unencrypted communication channel between a victim and target system. The attacker sniffs traffic
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-102-session-sidejacking
CAPEC-103 - MITRE CAPEC-103: Clickjacking (Standard Attack Pattern - High Severity)
MITRE CAPEC-103 (Clickjacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary tricks a victim into unknowingly initiating some action in one system while interacting with the UI from a seemingly completely differ
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-103-clickjacking
CAPEC-104 - MITRE CAPEC-104: Cross Zone Scripting (Standard Attack Pattern - High Severity)
MITRE CAPEC-104 (Cross Zone Scripting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to cause a victim to load content into their web-browser that bypasses security zone controls and gain access to increa
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-104-cross-zone-scripting
CAPEC-105 - MITRE CAPEC-105: HTTP Request Splitting (Detailed Attack Pattern - High Severity)
MITRE CAPEC-105 (HTTP Request Splitting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages by different intermediar
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-105-http-request-splitting
CAPEC-107 - MITRE CAPEC-107: Cross Site Tracing (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-107 (Cross Site Tracing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-107-cross-site-tracing
CAPEC-108 - MITRE CAPEC-108: Command Line Execution through SQL Injection (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-108 (Command Line Execution through SQL Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be d
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-108-command-line-execution-through-sql-injection
CAPEC-109 - MITRE CAPEC-109: Object Relational Mapping Injection (Detailed Attack Pattern - High Severity)
MITRE CAPEC-109 (Object Relational Mapping Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages a weakness present in the database access layer code generated with an Object Relational Mapping (ORM)
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-109-object-relational-mapping-injection
CAPEC-110 - MITRE CAPEC-110: SQL Injection through SOAP Parameter Tampering (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-110 (SQL Injection through SOAP Parameter Tampering) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies the parameters of the SOAP message that is sent from the service consumer to the service pro
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-110-sql-injection-through-soap-parameter-tampering
CAPEC-111 - MITRE CAPEC-111: JSON Hijacking (aka JavaScript Hijacking) (Standard Attack Pattern - High Severity)
MITRE CAPEC-111 (JSON Hijacking (aka JavaScript Hijacking)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker targets a system that uses JavaScript Object Notation (JSON) as a transport mechanism between the client a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-111-json-hijacking-aka-javascript-hijacking
CAPEC-112 - MITRE CAPEC-112: Brute Force (Meta Attack Pattern - High Severity)
MITRE CAPEC-112 (Brute Force) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack, some asset (information, functionality, identity, etc.) is protected by a finite secret value. The attacker attempts to gain access to t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-112-brute-force
CAPEC-113 - MITRE CAPEC-113: Interface Manipulation (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-113 (Interface Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the use or processing of an interface (e.g. Application Programming Interface (API) or System-on-Chip (SoC)) resulti
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-113-interface-manipulation
CAPEC-114 - MITRE CAPEC-114: Authentication Abuse (Attack Pattern - Medium Severity)
MITRE CAPEC-114 (Authentication Abuse) is an attack pattern in which an attacker obtains unauthorized access to an application, service, or device through knowledge of inherent weaknesses in an authentication mechanism, or by exploiting a flaw in the authentication scheme impleme
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-114-authentication-abuse
CAPEC-115 - MITRE CAPEC-115: Authentication Bypass (Attack Pattern - Medium Severity)
MITRE CAPEC-115 (Authentication Bypass) is an attack pattern in which an attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. This is distinct from credential thef
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-115-authentication-bypass
CAPEC-116 - MITRE CAPEC-116: Excavation (Attack Pattern - Information Disclosure)
MITRE CAPEC-116 (Excavation) is an attack pattern in which an adversary actively probes the target to solicit information that could be leveraged for malicious purposes - including stack traces, configuration data, or database design. Likelihood: High. Severity: Medium. Maps to C
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-116-excavation
CAPEC-117 - MITRE CAPEC-117: Interception (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-117 (Interception) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary monitors data streams to or from the target for information gathering purposes. This attack may be undertaken to solely gather sensitive i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-117-interception
CAPEC-120 - MITRE CAPEC-120: Double Encoding (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-120 (Double Encoding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary utilizes a repeating of the encoding process for a set of characters (that is, character encoding a character encoding of a charac
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-120-double-encoding
CAPEC-121 - MITRE CAPEC-121: Exploit Non-Production Interfaces (Standard Attack Pattern - High Severity)
MITRE CAPEC-121 (Exploit Non-Production Interfaces) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a sample, demonstration, test, or debug interface that is unintentionally enabled on a production system
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-121-exploit-non-production-interfaces
CAPEC-122 - MITRE CAPEC-122: Privilege Abuse (Attack Pattern - Medium Severity)
MITRE CAPEC-122 (Privilege Abuse) is an attack pattern in which an adversary exploits features of the target that should be reserved for privileged users or administrators but are exposed to use by lower or non-privileged accounts. Likelihood of attack: High. Typical severity: Me
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-122-privilege-abuse
CAPEC-123 - MITRE CAPEC-123: Buffer Manipulation (Meta Attack Pattern - Very High Severity)
MITRE CAPEC-123 (Buffer Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates an application's interaction with a buffer in an attempt to read or modify data they shouldn't have access to. Buffer a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-123-buffer-manipulation
CAPEC-124 - MITRE CAPEC-124: Shared Resource Manipulation (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-124 (Shared Resource Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a resource shared between multiple applications, an application pool or hardware pin multiplexing to affect behav
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-124-shared-resource-manipulation
CAPEC-125 - MITRE CAPEC-125: Flooding (Attack Pattern - Resource Exhaustion)
MITRE CAPEC-125 (Flooding) is an attack pattern in which an adversary consumes target resources by rapidly engaging in a large number of interactions. Exploits weaknesses in rate limiting and prevents legitimate access or causes system crashes. Severity: Medium. Maps to MITRE ATT
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-125-flooding
CAPEC-126 - MITRE CAPEC-126: Path Traversal (Attack Pattern - Very High Severity)
MITRE CAPEC-126 (Path Traversal) is an attack pattern in which an adversary exploits insufficient input validation to access unauthorized data by manipulating file paths, typically using dot-dot-slash sequences to traverse outside intended directory structures. Likelihood: High.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-126-path-traversal
CAPEC-127 - MITRE CAPEC-127: Directory Indexing (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-127 (Directory Indexing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary crafts a request to a target that results in the target listing/indexing the content of a directory as output. One common method
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-127-directory-indexing
CAPEC-128 - MITRE CAPEC-128: Integer Attacks (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-128 (Integer Attacks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker takes advantage of the structure of integer variables to cause these variables to assume values that are not expected by an applicat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-128-integer-attacks
CAPEC-129 - MITRE CAPEC-129: Pointer Manipulation (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-129 (Pointer Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack pattern involves an adversary manipulating a pointer within a target application resulting in the application accessing an unintend
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-129-pointer-manipulation
CAPEC-130 - MITRE CAPEC-130: Excessive Allocation (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-130 (Excessive Allocation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary causes the target to allocate excessive resources to servicing the attackers' request, thereby reducing the resources available fo
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-130-excessive-allocation
CAPEC-131 - MITRE CAPEC-131: Resource Leak Exposure (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-131 (Resource Leak Exposure) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary utilizes a resource leak on the target to deplete the quantity of the resource available to service legitimate requests. Likelih
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-131-resource-leak-exposure
CAPEC-132 - MITRE CAPEC-132: Symlink Attack (Detailed Attack Pattern - High Severity)
MITRE CAPEC-132 (Symlink Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary positions a symbolic link in such a manner that the targeted user or application accesses the link's endpoint, assuming that it is a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-132-symlink-attack
CAPEC-133 - MITRE CAPEC-133: Try All Common Switches (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-133 (Try All Common Switches) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker attempts to invoke all common switches and options in the target application for the purpose of discovering weaknesses in th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-133-try-all-common-switches
CAPEC-134 - MITRE CAPEC-134: Email Injection (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-134 (Email Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the headers and content of an email message by injecting data via the use of delimiter characters native to the protoco
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-134-email-injection
CAPEC-135 - MITRE CAPEC-135: Format String Injection (Standard Attack Pattern - High Severity)
MITRE CAPEC-135 (Format String Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary includes formatting characters in a string input field on the target application. Most applications assume that users will
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-135-format-string-injection
CAPEC-136 - MITRE CAPEC-136: LDAP Injection (Standard Attack Pattern - High Severity)
MITRE CAPEC-136 (LDAP Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates or crafts an LDAP query for the purpose of undermining the security of the target. Some applications use user input to cr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-136-ldap-injection
CAPEC-137 - MITRE CAPEC-137: Parameter Injection (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-137 (Parameter Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the content of request parameters for the purpose of undermining the security of the target. Some parameter encodings u
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-137-parameter-injection
CAPEC-138 - MITRE CAPEC-138: Reflection Injection (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-138 (Reflection Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary supplies a value to the target application which is then used by reflection methods to identify a class, method, or field. For
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-138-reflection-injection
CAPEC-139 - MITRE CAPEC-139: Relative Path Traversal (Detailed Attack Pattern - High Severity)
MITRE CAPEC-139 (Relative Path Traversal) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in input validation on the target by supplying a specially constructed path utilizing dot and slash char
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-139-relative-path-traversal
CAPEC-140 - MITRE CAPEC-140: Bypassing of Intermediate Forms in Multiple-Form Sets (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-140 (Bypassing of Intermediate Forms in Multiple-Form Sets) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some web applications require users to submit information through an ordered sequence of web forms. This i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-140-bypassing-of-intermediate-forms-in-multiple-form-sets
CAPEC-141 - MITRE CAPEC-141: Cache Poisoning (Standard Attack Pattern - High Severity)
MITRE CAPEC-141 (Cache Poisoning) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits the functionality of cache technologies to cause specific data to be cached that aids the attackers' objectives. This descr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-141-cache-poisoning
CAPEC-142 - MITRE CAPEC-142: DNS Cache Poisoning (Detailed Attack Pattern - High Severity)
MITRE CAPEC-142 (DNS Cache Poisoning) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A domain name server translates a domain name (such as www.example.com) into an IP address that Internet hosts use to contact Internet resou
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-142-dns-cache-poisoning
CAPEC-143 - MITRE CAPEC-143: Detect Unpublicized Web Pages (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-143 (Detect Unpublicized Web Pages) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary searches a targeted web site for web pages that have not been publicized. In doing this, the adversary may be able to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-143-detect-unpublicized-web-pages
CAPEC-144 - MITRE CAPEC-144: Detect Unpublicized Web Services (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-144 (Detect Unpublicized Web Services) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary searches a targeted web site for web services that have not been publicized. This attack can be especially dangero
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-144-detect-unpublicized-web-services
CAPEC-145 - MITRE CAPEC-145: Checksum Spoofing (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-145 (Checksum Spoofing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs a checksum message for the purpose of making a payload appear to have a valid corresponding checksum. Checksums are used t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-145-checksum-spoofing
CAPEC-146 - MITRE CAPEC-146: XML Schema Poisoning (Detailed Attack Pattern - High Severity)
MITRE CAPEC-146 (XML Schema Poisoning) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary corrupts or modifies the content of XML schema information passed between a client and server for the purpose of undermining t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-146-xml-schema-poisoning
CAPEC-147 - MITRE CAPEC-147: XML Ping of the Death (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-147 (XML Ping of the Death) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker initiates a resource depletion attack where a large number of small XML messages are delivered at a sufficiently rapid rate to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-147-xml-ping-of-the-death
CAPEC-148 - MITRE CAPEC-148: Content Spoofing (Attack Pattern - Medium Severity)
MITRE CAPEC-148 (Content Spoofing) is an attack pattern in which an adversary modifies content to make it contain something other than what the original content producer intended while keeping the apparent source unchanged. Encompasses modification of web pages, email messages, f
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-148-content-spoofing
CAPEC-149 - MITRE CAPEC-149: Explore for Predictable Temporary File Names (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-149 (Explore for Predictable Temporary File Names) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker explores a target to identify the names and locations of predictable temporary files for the purpose of
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-149-explore-for-predictable-temporary-file-names
CAPEC-150 - MITRE CAPEC-150: Collect Data from Common Resource Locations (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-150 (Collect Data from Common Resource Locations) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits well-known locations for resources for the purposes of undermining the security of the target.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-150-collect-data-from-common-resource-locations
CAPEC-151 - MITRE CAPEC-151: Identity Spoofing (Attack Pattern - Medium Severity)
MITRE CAPEC-151 (Identity Spoofing) is an attack pattern in which an adversary assumes the identity of another entity (human or non-human) and uses that identity to accomplish a goal. Likelihood and Severity: Medium. Maps to CWE-287 (Improper Authentication). Page lists robust au
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-151-identity-spoofing
CAPEC-153 - MITRE CAPEC-153: Input Data Manipulation (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-153 (Input Data Manipulation) is a meta-level attack pattern in which an attacker exploits a weakness in input validation by controlling the format, structure, and composition of data to an input-processing interface. Severity: Medium. Maps to CWE-20 (Improper Input V
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-153-input-data-manipulation
CAPEC-154 - MITRE CAPEC-154: Resource Location Spoofing (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-154 (Resource Location Spoofing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary deceives an application or user and convinces them to request a resource from an unintended location. By spoofing the locati
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-154-resource-location-spoofing
CAPEC-155 - MITRE CAPEC-155: Screen Temporary Files for Sensitive Information (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-155 (Screen Temporary Files for Sensitive Information) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits the temporary, insecure storage of information by monitoring the content of files used to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-155-screen-temporary-files-for-sensitive-information
CAPEC-157 - MITRE CAPEC-157: Sniffing Attacks (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-157 (Sniffing Attacks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary intercepts information transmitted between two third parties. The adversary must be able to observe, read
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-157-sniffing-attacks
CAPEC-158 - MITRE CAPEC-158: Sniffing Network Traffic (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-158 (Sniffing Network Traffic) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary monitors network traffic between nodes of a public or multicast network in an attempt to capture
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-158-sniffing-network-traffic
CAPEC-159 - MITRE CAPEC-159: Redirect Access to Libraries (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-159 (Redirect Access to Libraries) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in the way an application searches for external libraries to manipulate the execution flow to poin
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-159-redirect-access-to-libraries
CAPEC-160 - MITRE CAPEC-160: Exploit Script-Based APIs (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-160 (Exploit Script-Based APIs) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some APIs support scripting instructions as arguments. Methods that take scripted instructions (or references to scripted instructions
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-160-exploit-script-based-apis
CAPEC-161 - MITRE CAPEC-161: Infrastructure Manipulation (Meta Attack Pattern - High Severity)
MITRE CAPEC-161 (Infrastructure Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits characteristics of the infrastructure of a network entity in order to perpetrate attacks or information gathering o
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-161-infrastructure-manipulation
CAPEC-162 - MITRE CAPEC-162: Manipulating Hidden Fields (Detailed Attack Pattern - High Severity)
MITRE CAPEC-162 (Manipulating Hidden Fields) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in the server's trust of client-side processing by modifying data on the client-side, such as price
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-162-manipulating-hidden-fields
CAPEC-163 - MITRE CAPEC-163: Spear Phishing (Detailed Attack Pattern - High Severity)
MITRE CAPEC-163 (Spear Phishing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets a specific user or group with a Phishing (CAPEC-98) attack tailored to a category of users in order to have maximum relevanc
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-163-spear-phishing
CAPEC-164 - MITRE CAPEC-164: Mobile Phishing (Detailed Attack Pattern - High Severity)
MITRE CAPEC-164 (Mobile Phishing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets mobile phone users with a phishing attack for the purpose of soliciting account passwords or sensitive information from the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-164-mobile-phishing
CAPEC-165 - MITRE CAPEC-165: File Manipulation (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-165 (File Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies file contents or attributes (such as extensions or names) of files in a manner to cause incorrect processing by an applicatio
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-165-file-manipulation
CAPEC-166 - MITRE CAPEC-166: Force the System to Reset Values (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-166 (Force the System to Reset Values) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker forces the target into a previous state in order to leverage potential weaknesses in the target dependent upon a pr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-166-force-the-system-to-reset-values
CAPEC-167 - MITRE CAPEC-167: White Box Reverse Engineering (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-167 (White Box Reverse Engineering) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker discovers the structure, function, and composition of a type of computer software through white box analysis technique
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-167-white-box-reverse-engineering
CAPEC-168 - MITRE CAPEC-168: Windows ::DATA Alternate Data Stream (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-168 (Windows ::DATA Alternate Data Stream) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits the functionality of Microsoft NTFS Alternate Data Streams (ADS) to undermine system security. ADS all
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-168-windows-data-alternate-data-stream
CAPEC-169 - MITRE CAPEC-169: Footprinting (Meta Attack Pattern - Very Low Severity)
MITRE CAPEC-169 (Footprinting) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in probing and exploration activities to identify constituents and properties of the target. Likelihood of attack: High. Typical s
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-169-footprinting
CAPEC-170 - MITRE CAPEC-170: Web Application Fingerprinting (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-170 (Web Application Fingerprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker sends a series of probes to a web application in order to elicit version-dependent and type-dependent behavior that a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-170-web-application-fingerprinting
CAPEC-173 - MITRE CAPEC-173: Action Spoofing (Meta Attack Pattern - Very High Severity)
MITRE CAPEC-173 (Action Spoofing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary is able to disguise one action for another and therefore trick a user into initiating one type of action when they intend to initiate a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-173-action-spoofing
CAPEC-174 - MITRE CAPEC-174: Flash Parameter Injection (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-174 (Flash Parameter Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of improper data validation to inject malicious global parameters into a Flash file embedded within an HT
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-174-flash-parameter-injection
CAPEC-175 - MITRE CAPEC-175: Code Inclusion (Meta Attack Pattern - Very High Severity)
MITRE CAPEC-175 (Code Inclusion) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness on the target to force arbitrary code to be retrieved locally or from a remote location and executed. This differs f
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-175-code-inclusion
CAPEC-176 - MITRE CAPEC-176: Configuration/Environment Manipulation (Attack Pattern - Medium Severity)
MITRE CAPEC-176 (Configuration/Environment Manipulation) is an attack pattern in which an attacker manipulates files or settings external to a target application that affect the behavior of that application. Severity: Medium. Maps to CWE-15 (External Control of System or Configur
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-176-configuration-environment-manipulation
CAPEC-177 - MITRE CAPEC-177: Create files with the same name as files protected with a higher classification (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-177 (Create files with the same name as files protected with a higher classification) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits file location algorithms in an operating system or applicat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-177-create-files-with-the-same-name-as-files
CAPEC-178 - MITRE CAPEC-178: Cross-Site Flashing (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-178 (Cross-Site Flashing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to trick the victim into executing a Flash document that passes commands or calls to a Flash player browser plugin, allo
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-178-cross-site-flashing
CAPEC-179 - MITRE CAPEC-179: Calling Micro-Services Directly (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-179 (Calling Micro-Services Directly) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to discover and query Micro-services at a web location and thereby expose the Micro-services to further expl
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-179-calling-micro-services-directly
CAPEC-180 - MITRE CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-180 (Exploiting Incorrectly Configured Access Control Security Levels) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in the configuration of access controls and is able to bypass t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-180-exploiting-incorrectly-configured-access-control-security-le
CAPEC-181 - MITRE CAPEC-181: Flash File Overlay (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-181 (Flash File Overlay) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker creates a transparent overlay using flash in order to intercept user actions for the purpose of performing a clickjacking attack.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-181-flash-file-overlay
CAPEC-182 - MITRE CAPEC-182: Flash Injection (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-182 (Flash Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker tricks a victim to execute malicious flash content that executes commands or makes flash calls specified by the attacker. One exampl
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-182-flash-injection
CAPEC-183 - MITRE CAPEC-183: IMAP/SMTP Command Injection (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-183 (IMAP/SMTP Command Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits weaknesses in input validation on web-mail servers to execute commands on the IMAP/SMTP server. Web-mail serve
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-183-imap-smtp-command-injection
CAPEC-184 - MITRE CAPEC-184: Software Integrity Attack (Attack Pattern - Supply Chain Foundation)
MITRE CAPEC-184 (Software Integrity Attack) is an attack pattern in which an attacker initiates a series of events to cause a user, program, server, or device to perform actions that undermine the integrity of software code, device data structures, or device firmware. Typical sev
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-184-software-integrity-attack
CAPEC-185 - MITRE CAPEC-185: Malicious Software Download (Attack Pattern - Very High Severity)
MITRE CAPEC-185 (Malicious Software Download) is an attack pattern in which an attacker uses deceptive methods to cause a user or automated process to download and install dangerous code from an attacker-controlled source. Severity: Very High. Maps to CWE-494 (Download of Code Wi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-185-malicious-software-download
CAPEC-186 - MITRE CAPEC-186: Malicious Software Update (Standard Attack Pattern - High Severity)
MITRE CAPEC-186 (Malicious Software Update) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses deceptive methods to cause a user or an automated process to download and install dangerous code believed to be a va
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-186-malicious-software-update
CAPEC-187 - MITRE CAPEC-187: Malicious Automated Software Update via Redirection (Detailed Attack Pattern - High Severity)
MITRE CAPEC-187 (Malicious Automated Software Update via Redirection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits two layers of weaknesses in server or client software for automated update mechanisms t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-187-malicious-automated-software-update-via-redirection
CAPEC-188 - MITRE CAPEC-188: Reverse Engineering (Meta Attack Pattern - Low Severity)
MITRE CAPEC-188 (Reverse Engineering) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary discovers the structure, function, and composition of an object, resource, or system by using a variety of analysis techniques to e
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-188-reverse-engineering
CAPEC-189 - MITRE CAPEC-189: Black Box Reverse Engineering (Standard Attack Pattern - Low Severity)
MITRE CAPEC-189 (Black Box Reverse Engineering) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary discovers the structure, function, and composition of a type of computer software through black box analysis techniqu
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-189-black-box-reverse-engineering
CAPEC-190 - MITRE CAPEC-190: Reverse Engineer an Executable to Expose Assumed Hidden Functionality (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-190 (Reverse Engineer an Executable to Expose Assumed Hidden Functionality) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker analyzes a binary file or executable for the purpose of discovering the struct
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-190-reverse-engineer-an-executable-to-expose-assumed-hidden
CAPEC-191 - MITRE CAPEC-191: Read Sensitive Constants Within an Executable (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-191 (Read Sensitive Constants Within an Executable) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activities to discover any sensitive constants present within the compiled code of an exec
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-191-read-sensitive-constants-within-an-executable
CAPEC-192 - MITRE CAPEC-192: Protocol Analysis (Meta Attack Pattern - Low Severity)
MITRE CAPEC-192 (Protocol Analysis) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activities to decipher and/or decode protocol information for a network or application communication protocol used for tra
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-192-protocol-analysis
CAPEC-193 - MITRE CAPEC-193: PHP Remote File Inclusion (Detailed Attack Pattern - High Severity)
MITRE CAPEC-193 (PHP Remote File Inclusion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this pattern the adversary is able to load and execute arbitrary code remotely available from the application. This is usually acco
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-193-php-remote-file-inclusion
CAPEC-194 - MITRE CAPEC-194: Fake the Source of Data (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-194 (Fake the Source of Data) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of improper authentication to provide data or services under a falsified identity. The purpose of using the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-194-fake-the-source-of-data
CAPEC-195 - MITRE CAPEC-195: Principal Spoof (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-195 (Principal Spoof) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A Principal Spoof is a form of Identity Spoofing where an adversary pretends to be some other person in an interaction. This is often accomplish
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-195-principal-spoof
CAPEC-196 - MITRE CAPEC-196: Session Credential Falsification through Forging (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-196 (Session Credential Falsification through Forging) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker creates a false but functional session credential in order to gain or usurp access to a service. Se
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-196-session-credential-falsification-through-forging
CAPEC-197 - MITRE CAPEC-197: Exponential Data Expansion (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-197 (Exponential Data Expansion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary submits data to a target application which contains nested exponential data expansion to produce excessively large outpu
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-197-exponential-data-expansion
CAPEC-198 - MITRE CAPEC-198: XSS Targeting Error Pages (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-198 (XSS Targeting Error Pages) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary distributes a link (or possibly some other query structure) with a request to a third party web server that is malformed
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-198-xss-targeting-error-pages
CAPEC-199 - MITRE CAPEC-199: XSS Using Alternate Syntax (Detailed Attack Pattern - High Severity)
MITRE CAPEC-199 (XSS Using Alternate Syntax) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses alternate forms of keywords or commands that result in the same action as the primary form but which may not be cau
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-199-xss-using-alternate-syntax
CAPEC-200 - MITRE CAPEC-200: Removal of filters: Input filters, output filters, data masking (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-200 (Removal of filters: Input filters, output filters, data masking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker removes or disables filtering mechanisms on the target application. Input filters pr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-200-removal-of-filters-input-filters-output-filters-data
CAPEC-201 - MITRE CAPEC-201: Serialized Data External Linking (Detailed Attack Pattern - High Severity)
MITRE CAPEC-201 (Serialized Data External Linking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a serialized data file (e.g. XML, YAML, etc...) that contains an external data reference. Because serializ
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-201-serialized-data-external-linking
CAPEC-202 - MITRE CAPEC-202: Create Malicious Client (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-202 (Create Malicious Client) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a client application to interface with a target service where the client violates assumptions the service makes abo
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-202-create-malicious-client
CAPEC-203 - MITRE CAPEC-203: Manipulate Registry Information (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-203 (Manipulate Registry Information) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authorization in order to modify content within a registry (e.g., Windows Registry, Mac plis
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-203-manipulate-registry-information
CAPEC-204 - MITRE CAPEC-204: Lifting Sensitive Data Embedded in Cache (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-204 (Lifting Sensitive Data Embedded in Cache) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary examines a target application's cache, or a browser cache, for sensitive information. Many applications th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-204-lifting-sensitive-data-embedded-in-cache
CAPEC-206 - MITRE CAPEC-206: Signing Malicious Code (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-206 (Signing Malicious Code) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary extracts credentials used for code signing from a production environment and then uses these credentials to sign malicious
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-206-signing-malicious-code
CAPEC-207 - MITRE CAPEC-207: Removing Important Client Functionality (Standard Attack Pattern - High Severity)
MITRE CAPEC-207 (Removing Important Client Functionality) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary removes or disables functionality on the client that the server assumes to be present and trustworthy. Like
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-207-removing-important-client-functionality
CAPEC-208 - MITRE CAPEC-208: Removing/short-circuiting 'Purse' logic: removing/mutating 'cash' decrements (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-208 (Removing/short-circuiting 'Purse' logic: removing/mutating 'cash' decrements) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker removes or modifies the logic on a client associated with monetary calc
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-208-removing-short-circuiting-purse-logic-removing-mutating-cash
CAPEC-209 - MITRE CAPEC-209: XSS Using MIME Type Mismatch (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-209 (XSS Using MIME Type Mismatch) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a file with scripting content but where the specified MIME type of the file is such that scripting is not expe
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-209-xss-using-mime-type-mismatch
CAPEC-212 - MITRE CAPEC-212: Functionality Misuse (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-212 (Functionality Misuse) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages a legitimate capability of an application in such a way as to achieve a negative technical impact. The system functional
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-212-functionality-misuse
CAPEC-215 - MITRE CAPEC-215: Fuzzing for application mapping (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-215 (Fuzzing for application mapping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker sends random, malformed, or otherwise unexpected messages to a target application and observes the application's log
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-215-fuzzing-for-application-mapping
CAPEC-216 - MITRE CAPEC-216: Communication Channel Manipulation (Meta Attack Pattern)
MITRE CAPEC-216 (Communication Channel Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates a setting or parameter on communications channel in order to compromise its security. This can result in
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-216-communication-channel-manipulation
CAPEC-217 - MITRE CAPEC-217: Exploiting Incorrectly Configured SSL/TLS (Standard Attack Pattern)
MITRE CAPEC-217 (Exploiting Incorrectly Configured SSL/TLS) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of incorrectly configured SSL/TLS communications that enables access to data intended to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-217-exploiting-incorrectly-configured-ssl-tls
CAPEC-218 - MITRE CAPEC-218: Spoofing of UDDI/ebXML Messages (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-218 (Spoofing of UDDI/ebXML Messages) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker spoofs a UDDI, ebXML, or similar message in order to impersonate a service provider in an e-business transaction. UD
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-218-spoofing-of-uddi-ebxml-messages
CAPEC-219 - MITRE CAPEC-219: XML Routing Detour Attacks (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-219 (XML Routing Detour Attacks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker subverts an intermediate system used to process XML content and forces the intermediate to modify and/or re-route the pro
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-219-xml-routing-detour-attacks
CAPEC-220 - MITRE CAPEC-220: Client-Server Protocol Manipulation (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-220 (Client-Server Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of weaknesses in the protocol by which a client and server are communicating to perform unexpec
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-220-client-server-protocol-manipulation
CAPEC-221 - MITRE CAPEC-221: Data Serialization External Entities Blowup (Detailed Attack Pattern)
MITRE CAPEC-221 (Data Serialization External Entities Blowup) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack takes advantage of the entity replacement property of certain data serialization languages (e.g., XML, Y
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-221-data-serialization-external-entities-blowup
CAPEC-222 - MITRE CAPEC-222: iFrame Overlay (Detailed Attack Pattern - High Severity)
MITRE CAPEC-222 (iFrame Overlay) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In an iFrame overlay attack the victim is tricked into unknowingly initiating some action in one system while interacting with the UI from seemin
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-222-iframe-overlay
CAPEC-224 - MITRE CAPEC-224: Fingerprinting (Meta Attack Pattern - Very Low Severity)
MITRE CAPEC-224 (Fingerprinting) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary compares output from a target system to known indicators that uniquely identify specific details about the target. Most commonly, finger
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-224-fingerprinting
CAPEC-226 - MITRE CAPEC-226: Session Credential Falsification through Manipulation (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-226 (Session Credential Falsification through Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates an existing credential in order to gain access to a target application. Session cr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-226-session-credential-falsification-through-manipulation
CAPEC-227 - MITRE CAPEC-227: Sustained Client Engagement (Meta Attack Pattern)
MITRE CAPEC-227 (Sustained Client Engagement) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attempts to deny legitimate users access to a resource by continually engaging a specific resource in an attempt to keep th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-227-sustained-client-engagement
CAPEC-228 - MITRE CAPEC-228: DTD Injection (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-228 (DTD Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker injects malicious content into an application's DTD in an attempt to produce a negative technical impact. DTDs are used to describe ho
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-228-dtd-injection
CAPEC-229 - MITRE CAPEC-229: Serialized Data Parameter Blowup (Detailed Attack Pattern - High Severity)
MITRE CAPEC-229 (Serialized Data Parameter Blowup) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack exploits certain serialized data parsers (e.g., XML, YAML, etc.) which manage data in an inefficient manner. The at
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-229-serialized-data-parameter-blowup
CAPEC-230 - MITRE CAPEC-230: Serialized Data with Nested Payloads (Standard Attack Pattern - High Severity)
MITRE CAPEC-230 (Serialized Data with Nested Payloads) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Applications often need to transform data in and out of a data format (e.g., XML and YAML) by using a parser. It may be pos
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-230-serialized-data-with-nested-payloads
CAPEC-231 - MITRE CAPEC-231: Oversized Serialized Data Payloads (Standard Attack Pattern - High Severity)
MITRE CAPEC-231 (Oversized Serialized Data Payloads) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary injects oversized serialized data payloads into a parser during data processing to produce adverse effects upon
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-231-oversized-serialized-data-payloads
CAPEC-233 - MITRE CAPEC-233: Privilege Escalation (Meta Attack Pattern)
MITRE CAPEC-233 (Privilege Escalation) is a meta-level attack pattern in which an adversary exploits a weakness enabling elevation of privilege to perform unauthorized actions. Page references OWASP Web Security Testing Guide for testing. Maps to MITRE ATT&CK T1548 (Abuse Elevati
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-233-privilege-escalation
CAPEC-234 - MITRE CAPEC-234: Hijacking a privileged process (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-234 (Hijacking a privileged process) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gains control of a process that is assigned elevated privileges in order to execute arbitrary code with those privil
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-234-hijacking-a-privileged-process
CAPEC-237 - MITRE CAPEC-237: Escaping a Sandbox by Calling Code in Another Language (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-237 (Escaping a Sandbox by Calling Code in Another Language) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker may submit malicious code of another language to obtain access to privileges that were not i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-237-escaping-a-sandbox-by-calling-code-in-another
CAPEC-240 - MITRE CAPEC-240: Resource Injection (Meta Attack Pattern - High Severity)
MITRE CAPEC-240 (Resource Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits weaknesses in input validation by manipulating resource identifiers enabling the unintended modification or specification o
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-240-resource-injection
CAPEC-242 - MITRE CAPEC-242: Code Injection (Meta Attack Pattern - High Severity)
MITRE CAPEC-242 (Code Injection) is a meta-level attack pattern in which an adversary exploits a weakness in input validation on the target to inject new code into that which is currently executing. Likelihood of attack: High. Typical severity: High. CAPEC-242 is the parent patte
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-242-code-injection
CAPEC-243 - MITRE CAPEC-243: XSS Targeting HTML Attributes (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-243 (XSS Targeting HTML Attributes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts commands to perform cross-site scripting (XSS) actions in HTML attributes. Many filters do not adequately san
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-243-xss-targeting-html-attributes
CAPEC-244 - MITRE CAPEC-244: XSS Targeting URI Substitution Fields (Detailed Attack Pattern - High Severity)
MITRE CAPEC-244 (XSS Targeting URI Substitution Fields) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits the ability of most browsers to interpret "data", "javascript" or other URI schemes as cli
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-244-xss-targeting-uri-substitution-fields
CAPEC-245 - MITRE CAPEC-245: XSS Using Doubled Characters (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-245 (XSS Using Doubled Characters) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary bypasses input validation by using doubled characters in order to perform a cross-site scripting attack. Some filters
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-245-xss-using-doubled-characters
CAPEC-247 - MITRE CAPEC-247: XSS Using Invalid Characters (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-247 (XSS Using Invalid Characters) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts invalid characters in identifiers to bypass application filtering of input. Filters may not scan beyond invali
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-247-xss-using-invalid-characters
CAPEC-248 - MITRE CAPEC-248: Command Injection (Meta Attack Pattern - High Severity)
MITRE CAPEC-248 (Command Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary looking to execute a command of their choosing, injects new items into an existing command thus modifying interpretation away from wh
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-248-command-injection
CAPEC-250 - MITRE CAPEC-250: XML Injection (Attack Pattern - High Severity)
MITRE CAPEC-250 (XML Injection) is an attack pattern in which an attacker uses crafted XML user-controllable input to probe, attack, and inject data into the XML database using techniques similar to SQL injection. Likelihood: High. Maps to CWE-91 (XML Injection / Blind XPath Inje
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-250-xml-injection
CAPEC-251 - MITRE CAPEC-251: Local Code Inclusion (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-251 (Local Code Inclusion) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker forces an application to load arbitrary code files from the local machine. The attacker could use this to try to load old vers
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-251-local-code-inclusion
CAPEC-252 - MITRE CAPEC-252: PHP Local File Inclusion (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-252 (PHP Local File Inclusion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker loads and executes an arbitrary local PHP file on a target machine. The attacker could use this to try to load old version
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-252-php-local-file-inclusion
CAPEC-253 - MITRE CAPEC-253: Remote Code Inclusion (Standard Attack Pattern)
MITRE CAPEC-253 (Remote Code Inclusion) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker forces an application to load arbitrary code files from a remote location. The attacker could use this to try to load old ver
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-253-remote-code-inclusion
CAPEC-256 - MITRE CAPEC-256: SOAP Array Overflow (Detailed Attack Pattern - High Severity)
MITRE CAPEC-256 (SOAP Array Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker sends a SOAP request with an array whose actual length exceeds the length indicated in the request. If the server processing the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-256-soap-array-overflow
CAPEC-261 - MITRE CAPEC-261: Fuzzing for garnering other adjacent user/sensitive data (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-261 (Fuzzing for garnering other adjacent user/sensitive data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary who is authorized to send queries to a target sends variants of expected queries in the ho
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-261-fuzzing-for-garnering-other-adjacent-user-sensitive-data
CAPEC-263 - MITRE CAPEC-263: Force Use of Corrupted Files (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-263 (Force Use of Corrupted Files) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This describes an attack where an application is forced to use a file that an attacker has corrupted. The result is often a denial
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-263-force-use-of-corrupted-files
CAPEC-267 - MITRE CAPEC-267: Leverage Alternate Encoding (Standard Attack Pattern - High Severity)
MITRE CAPEC-267 (Leverage Alternate Encoding) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages the possibility to encode potentially harmful input or content used by applications such that the application
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-267-leverage-alternate-encoding
CAPEC-268 - MITRE CAPEC-268: Audit Log Manipulation (Standard Attack Pattern)
MITRE CAPEC-268 (Audit Log Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The attacker injects, manipulates, deletes, or forges malicious log entries into the log file, in an attempt to mislead an audit of the l
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-268-audit-log-manipulation
CAPEC-270 - MITRE CAPEC-270: Modification of Registry Run Keys (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-270 (Modification of Registry Run Keys) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds a new entry to the "run keys" in the Windows registry so that an application of their choosing is executed w
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-270-modification-of-registry-run-keys
CAPEC-271 - MITRE CAPEC-271: Schema Poisoning (Standard Attack Pattern - High Severity)
MITRE CAPEC-271 (Schema Poisoning) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary corrupts or modifies the content of a schema for the purpose of undermining the security of the target. Schemas provide the struct
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-271-schema-poisoning
CAPEC-272 - MITRE CAPEC-272: Protocol Manipulation (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-272 (Protocol Manipulation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary subverts a communications protocol to perform an attack. This type of attack can allow an adversary to impersonate others, discov
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-272-protocol-manipulation
CAPEC-273 - MITRE CAPEC-273: HTTP Response Smuggling (Detailed Attack Pattern - High Severity)
MITRE CAPEC-273 (HTTP Response Smuggling) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates and injects malicious content in the form of secret unauthorized HTTP responses, into a single HTTP response fr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-273-http-response-smuggling
CAPEC-274 - MITRE CAPEC-274: HTTP Verb Tampering (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-274 (HTTP Verb Tampering) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies the HTTP Verb (e.g. GET, PUT, TRACE, etc.) in order to bypass access restrictions. Some web environments allow administ
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-274-http-verb-tampering
CAPEC-275 - MITRE CAPEC-275: DNS Rebinding (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-275 (DNS Rebinding) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary serves content whose IP address is resolved by a DNS server that the adversary controls. After initial contact by a web browser (or s
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-275-dns-rebinding
CAPEC-276 - MITRE CAPEC-276: Inter-component Protocol Manipulation (Standard Attack Pattern)
MITRE CAPEC-276 (Inter-component Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Inter-component protocols are used to communicate between different software and hardware modules within a single computer
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-276-inter-component-protocol-manipulation
CAPEC-277 - MITRE CAPEC-277: Data Interchange Protocol Manipulation (Standard Attack Pattern)
MITRE CAPEC-277 (Data Interchange Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Data Interchange Protocols are used to transmit structured data between entities. These protocols are often specific to a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-277-data-interchange-protocol-manipulation
CAPEC-278 - MITRE CAPEC-278: Web Services Protocol Manipulation (Standard Attack Pattern)
MITRE CAPEC-278 (Web Services Protocol Manipulation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates a web service related protocol to cause a web application or service to react differently than inten
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-278-web-services-protocol-manipulation
CAPEC-279 - MITRE CAPEC-279: SOAP Manipulation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-279 (SOAP Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Simple Object Access Protocol (SOAP) is used as a communication protocol between a client and server to invoke web services on the server. It
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-279-soap-manipulation
CAPEC-285 - MITRE CAPEC-285: ICMP Echo Request Ping (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-285 (ICMP Echo Request Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends out an ICMP Type 8 Echo Request, commonly known as a 'Ping', in order to determine if a target system is responsive. I
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-285-icmp-echo-request-ping
CAPEC-287 - MITRE CAPEC-287: TCP SYN Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-287 (TCP SYN Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a SYN scan to determine the status of ports on the remote target. SYN scanning is the most common type of port scanning that is u
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-287-tcp-syn-scan
CAPEC-290 - MITRE CAPEC-290: Enumerate Mail Exchange (MX) Records (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-290 (Enumerate Mail Exchange (MX) Records) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary enumerates the MX records for a given via a DNS query. This type of information gathering returns the names of
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-290-enumerate-mail-exchange-mx-records
CAPEC-291 - MITRE CAPEC-291: DNS Zone Transfers (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-291 (DNS Zone Transfers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a DNS misconfiguration that permits a ZONE transfer. Some external DNS servers will return a list of IP address and vali
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-291-dns-zone-transfers
CAPEC-292 - MITRE CAPEC-292: Host Discovery (Standard Attack Pattern - Low Severity)
MITRE CAPEC-292 (Host Discovery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a probe to an IP address to determine if the host is alive. Host discovery is one of the earliest phases of network reconnaiss
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-292-host-discovery
CAPEC-293 - MITRE CAPEC-293: Traceroute Route Enumeration (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-293 (Traceroute Route Enumeration) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a traceroute utility to map out the route which data flows through the network in route to a target destination.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-293-traceroute-route-enumeration
CAPEC-294 - MITRE CAPEC-294: ICMP Address Mask Request (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-294 (ICMP Address Mask Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends an ICMP Type 17 Address Mask Request to gather information about a target's networking configuration. ICMP Address
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-294-icmp-address-mask-request
CAPEC-295 - MITRE CAPEC-295: Timestamp Request (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-295 (Timestamp Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack leverages standard requests to learn the exact time associated with a target system. An adversary may be able to use th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-295-timestamp-request
CAPEC-296 - MITRE CAPEC-296: ICMP Information Request (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-296 (ICMP Information Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends an ICMP Information Request to a host to determine if it will respond to this deprecated mechanism. ICMP Information
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-296-icmp-information-request
CAPEC-297 - MITRE CAPEC-297: TCP ACK Ping (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-297 (TCP ACK Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a TCP segment with the ACK flag set to a remote host for the purpose of determining if the host is alive. This is one of several
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-297-tcp-ack-ping
CAPEC-298 - MITRE CAPEC-298: UDP Ping (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-298 (UDP Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a UDP datagram to the remote host to determine if the host is alive. If a UDP datagram is sent to an open UDP port there is very oft
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-298-udp-ping
CAPEC-299 - MITRE CAPEC-299: TCP SYN Ping (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-299 (TCP SYN Ping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses TCP SYN packets as a means towards host discovery. Typical RFC 793 behavior specifies that when a TCP port is open, a host must r
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-299-tcp-syn-ping
CAPEC-300 - MITRE CAPEC-300: Port Scanning (Standard Attack Pattern - Low Severity)
MITRE CAPEC-300 (Port Scanning) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a combination of techniques to determine the state of the ports on a remote target. Any service or application available for TCP
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-300-port-scanning
CAPEC-301 - MITRE CAPEC-301: TCP Connect Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-301 (TCP Connect Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses full TCP connection attempts to determine if a port is open on the target system. The scanning process involves completing a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-301-tcp-connect-scan
CAPEC-302 - MITRE CAPEC-302: TCP FIN Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-302 (TCP FIN Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a TCP FIN scan to determine if ports are closed on the target machine. This scan type is accomplished by sending TCP segments wit
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-302-tcp-fin-scan
CAPEC-303 - MITRE CAPEC-303: TCP Xmas Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-303 (TCP Xmas Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a TCP XMAS scan to determine if ports are closed on the target machine. This scan type is accomplished by sending TCP segments w
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-303-tcp-xmas-scan
CAPEC-304 - MITRE CAPEC-304: TCP Null Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-304 (TCP Null Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a TCP NULL scan to determine if ports are closed on the target machine. This scan type is accomplished by sending TCP segments w
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-304-tcp-null-scan
CAPEC-305 - MITRE CAPEC-305: TCP ACK Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-305 (TCP ACK Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses TCP ACK segments to gather information about firewall or ACL configuration. The purpose of this type of scan is to discover infor
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-305-tcp-ack-scan
CAPEC-306 - MITRE CAPEC-306: TCP Window Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-306 (TCP Window Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in TCP Window scanning to analyze port status and operating system type. TCP Window scanning uses the ACK scanning method b
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-306-tcp-window-scan
CAPEC-307 - MITRE CAPEC-307: TCP RPC Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-307 (TCP RPC Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary scans for RPC services listing on a Unix/Linux host. Likelihood of attack: Unknown. Typical severity: Low. Maps to weaknesses CWE-200.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-307-tcp-rpc-scan
CAPEC-308 - MITRE CAPEC-308: UDP Scan (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-308 (UDP Scan) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in UDP scanning to gather information about UDP port status on the target system. UDP scanning methods involve sending a UDP datag
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-308-udp-scan
CAPEC-309 - MITRE CAPEC-309: Network Topology Mapping (Standard Attack Pattern - Low Severity)
MITRE CAPEC-309 (Network Topology Mapping) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in scanning activities to map network nodes, hosts, devices, and routes. Adversaries usually perform this type of
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-309-network-topology-mapping
CAPEC-310 - MITRE CAPEC-310: Scanning for Vulnerable Software (Attack Pattern - Reconnaissance)
MITRE CAPEC-310 (Scanning for Vulnerable Software) is a reconnaissance attack pattern in which an adversary engages in scanning activity to find vulnerable software versions or types (operating systems, network services). Typically follows port scanning. Severity: Low (recon phas
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-310-scanning-for-vulnerable-software
CAPEC-312 - MITRE CAPEC-312: Active OS Fingerprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-312 (Active OS Fingerprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activity to detect the operating system or firmware version of a remote target by interrogating a device, serve
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-312-active-os-fingerprinting
CAPEC-313 - MITRE CAPEC-313: Passive OS Fingerprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-313 (Passive OS Fingerprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in activity to detect the version or type of OS software in a an environment by passively monitoring communicatio
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-313-passive-os-fingerprinting
CAPEC-317 - MITRE CAPEC-317: IP ID Sequencing Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-317 (IP ID Sequencing Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe analyzes the IP 'ID' field sequence number generation algorithm of a remote host. Operating systems generate
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-317-ip-id-sequencing-probe
CAPEC-318 - MITRE CAPEC-318: IP 'ID' Echoed Byte-Order Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-318 (IP 'ID' Echoed Byte-Order Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests to determine if the remote host echoes back the IP 'ID' value from the probe packet. An attac
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-318-ip-id-echoed-byte-order-probe
CAPEC-319 - MITRE CAPEC-319: IP (DF) 'Don't Fragment Bit' Echoing Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-319 (IP (DF) 'Don't Fragment Bit' Echoing Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests to determine if the remote host echoes back the IP 'DF' (Don't Fragment) bit in a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-319-ip-df-don-t-fragment-bit-echoing-probe
CAPEC-320 - MITRE CAPEC-320: TCP Timestamp Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-320 (TCP Timestamp Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe examines the remote server's implementation of TCP timestamps. Not all operating systems implement timestamps w
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-320-tcp-timestamp-probe
CAPEC-321 - MITRE CAPEC-321: TCP Sequence Number Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-321 (TCP Sequence Number Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests the target system's assignment of TCP sequence numbers. One common way to test TCP Sequence Number
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-321-tcp-sequence-number-probe
CAPEC-322 - MITRE CAPEC-322: TCP (ISN) Greatest Common Divisor Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-322 (TCP (ISN) Greatest Common Divisor Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe sends a number of TCP SYN packets to an open port of a remote machine. The Initial Sequence
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-322-tcp-isn-greatest-common-divisor-probe
CAPEC-323 - MITRE CAPEC-323: TCP (ISN) Counter Rate Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-323 (TCP (ISN) Counter Rate Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS detection probe measures the average rate of initial sequence number increments during a period of time. Sequence numbers a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-323-tcp-isn-counter-rate-probe
CAPEC-324 - MITRE CAPEC-324: TCP (ISN) Sequence Predictability Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-324 (TCP (ISN) Sequence Predictability Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of operating system probe attempts to determine an estimate for how predictable the sequence number generation
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-324-tcp-isn-sequence-predictability-probe
CAPEC-325 - MITRE CAPEC-325: TCP Congestion Control Flag (ECN) Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-325 (TCP Congestion Control Flag (ECN) Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe checks to see if the remote host supports explicit congestion notification (ECN) messaging.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-325-tcp-congestion-control-flag-ecn-probe
CAPEC-326 - MITRE CAPEC-326: TCP Initial Window Size Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-326 (TCP Initial Window Size Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe checks the initial TCP Window size. TCP stacks limit the range of sequence numbers allowable within a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-326-tcp-initial-window-size-probe
CAPEC-327 - MITRE CAPEC-327: TCP Options Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-327 (TCP Options Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe analyzes the type and order of any TCP header options present within a response segment. Most operating systems u
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-327-tcp-options-probe
CAPEC-328 - MITRE CAPEC-328: TCP 'RST' Flag Checksum Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-328 (TCP 'RST' Flag Checksum Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe performs a checksum on any ASCII data contained within the data portion or a RST packet. Some operati
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-328-tcp-rst-flag-checksum-probe
CAPEC-329 - MITRE CAPEC-329: ICMP Error Message Quoting Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-329 (ICMP Error Message Quoting Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a technique to generate an ICMP Error message (Port Unreachable, Destination Unreachable, Redirect, Source Qu
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-329-icmp-error-message-quoting-probe
CAPEC-330 - MITRE CAPEC-330: ICMP Error Message Echoing Integrity Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-330 (ICMP Error Message Echoing Integrity Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a technique to generate an ICMP Error message (Port Unreachable, Destination Unreachable, Redirect,
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-330-icmp-error-message-echoing-integrity-probe
CAPEC-331 - MITRE CAPEC-331: ICMP IP Total Length Field Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-331 (ICMP IP Total Length Field Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a UDP packet to a closed port on the target machine to solicit an IP Header's total length field value withi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-331-icmp-ip-total-length-field-probe
CAPEC-332 - MITRE CAPEC-332: ICMP IP 'ID' Field Error Message Probe (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-332 (ICMP IP 'ID' Field Error Message Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a UDP datagram having an assigned value to its internet identification field (ID) to a closed port on
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-332-icmp-ip-id-field-error-message-probe
CAPEC-383 - MITRE CAPEC-383: Harvesting Information via API Event Monitoring (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-383 (Harvesting Information via API Event Monitoring) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary hosts an event within an application framework and then monitors the data exchanged during the cour
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-383-harvesting-information-via-api-event-monitoring
CAPEC-384 - MITRE CAPEC-384: Application API Message Manipulation via Man-in-the-Middle (Standard Attack Pattern - Low Severity)
MITRE CAPEC-384 (Application API Message Manipulation via Man-in-the-Middle) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-384-application-api-message-manipulation-via-man-in-the
CAPEC-385 - MITRE CAPEC-385: Transaction or Event Tampering via Application API Manipulation (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-385 (Transaction or Event Tampering via Application API Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker hosts or joins an event or transaction within an application framework in order to c
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-385-transaction-or-event-tampering-via-application-api-manipulat
CAPEC-386 - MITRE CAPEC-386: Application API Navigation Remapping (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-386 (Application API Navigation Remapping) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework in order to change the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-386-application-api-navigation-remapping
CAPEC-387 - MITRE CAPEC-387: Navigation Remapping To Propagate Malicious Content (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-387 (Navigation Remapping To Propagate Malicious Content) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates either egress or ingress data from a client within an application framework in orde
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-387-navigation-remapping-to-propagate-malicious-content
CAPEC-388 - MITRE CAPEC-388: Application API Button Hijacking (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-388 (Application API Button Hijacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework in order to change the dest
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-388-application-api-button-hijacking
CAPEC-389 - MITRE CAPEC-389: Content Spoofing Via Application API Manipulation (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-389 (Content Spoofing Via Application API Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker manipulates either egress or ingress data from a client within an application framework in order t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-389-content-spoofing-via-application-api-manipulation
CAPEC-390 - MITRE CAPEC-390: Bypassing Physical Security (Meta Attack Pattern - Unrated Severity)
MITRE CAPEC-390 (Bypassing Physical Security) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Facilities often used layered models for physical security such as traditional locks, Electronic-based card entry systems, coupled with
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-390-bypassing-physical-security
CAPEC-391 - MITRE CAPEC-391: Bypassing Physical Locks (Standard Attack Pattern - Unrated Severity)
MITRE CAPEC-391 (Bypassing Physical Locks) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses techniques and methods to bypass physical security measures of a building or facility. Physical locks may range from t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-391-bypassing-physical-locks
CAPEC-392 - MITRE CAPEC-392: Lock Bumping (Detailed Attack Pattern - Unrated Severity)
MITRE CAPEC-392 (Lock Bumping) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses a bump key to force a lock on a building or facility and gain entry. Lock Bumping is the use of a special type of key that can be
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-392-lock-bumping
CAPEC-393 - MITRE CAPEC-393: Lock Picking (Detailed Attack Pattern - Unrated Severity)
MITRE CAPEC-393 (Lock Picking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses lock picking tools and techniques to bypass the locks on a building or facility. Lock picking is the use of a special set of tools
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-393-lock-picking
CAPEC-394 - MITRE CAPEC-394: Using a Snap Gun Lock to Force a Lock (Detailed Attack Pattern - Unrated Severity)
MITRE CAPEC-394 (Using a Snap Gun Lock to Force a Lock) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses a Snap Gun, also known as a Pick Gun, to force the lock on a building or facility. A Pick Gun is a specia
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-394-using-a-snap-gun-lock-to-force-a-lock
CAPEC-395 - MITRE CAPEC-395: Bypassing Electronic Locks and Access Controls (Standard Attack Pattern - Unrated Severity)
MITRE CAPEC-395 (Bypassing Electronic Locks and Access Controls) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits security assumptions to bypass electronic locks or other forms of access controls. Most atta
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-395-bypassing-electronic-locks-and-access-controls
CAPEC-397 - MITRE CAPEC-397: Cloning Magnetic Strip Cards (Detailed Attack Pattern - Unrated Severity)
MITRE CAPEC-397 (Cloning Magnetic Strip Cards) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker duplicates the data on a Magnetic strip card (i.e. 'swipe card' or 'magstripe') to gain unauthorized access to a physic
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-397-cloning-magnetic-strip-cards
CAPEC-398 - MITRE CAPEC-398: Magnetic Strip Card Brute Force Attacks (Detailed Attack Pattern)
MITRE CAPEC-398 (Magnetic Strip Card Brute Force Attacks) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary analyzes the data on two or more magnetic strip cards and is able to generate new cards containing valid se
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-398-magnetic-strip-card-brute-force-attacks
CAPEC-399 - MITRE CAPEC-399: Cloning RFID Cards or Chips (Detailed Attack Pattern - Unrated Severity)
MITRE CAPEC-399 (Cloning RFID Cards or Chips) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker analyzes data returned by an RFID chip and uses this information to duplicate a RFID signal that responds identically to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-399-cloning-rfid-cards-or-chips
CAPEC-400 - MITRE CAPEC-400: RFID Chip Deactivation or Destruction (Detailed Attack Pattern - Unrated Severity)
MITRE CAPEC-400 (RFID Chip Deactivation or Destruction) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses methods to deactivate a passive RFID tag for the purpose of rendering the tag, badge, card, or object con
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-400-rfid-chip-deactivation-or-destruction
CAPEC-401 - MITRE CAPEC-401: Physically Hacking Hardware (Standard Attack Pattern - High Severity)
MITRE CAPEC-401 (Physically Hacking Hardware) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in access control to gain access to currently installed hardware and precedes to implement changes
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-401-physically-hacking-hardware
CAPEC-402 - MITRE CAPEC-402: Bypassing ATA Password Security (Detailed Attack Pattern)
MITRE CAPEC-402 (Bypassing ATA Password Security) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in ATA security on a drive to gain access to the information the drive contains without supplyi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-402-bypassing-ata-password-security
CAPEC-406 - MITRE CAPEC-406: Dumpster Diving (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-406 (Dumpster Diving) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary cases an establishment and searches through trash bins, dumpsters, or areas where company information may have been accidentally di
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-406-dumpster-diving
CAPEC-407 - MITRE CAPEC-407: Pretexting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-407 (Pretexting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior to solicit information from target persons, or manipulate the target into performing some action that ser
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-407-pretexting
CAPEC-410 - MITRE CAPEC-410: Information Elicitation (Meta Attack Pattern - Low Severity)
MITRE CAPEC-410 (Information Elicitation) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages an individual using any combination of social engineering methods for the purpose of extracting information. Accurate c
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-410-information-elicitation
CAPEC-412 - MITRE CAPEC-412: Pretexting via Customer Service (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-412 (Pretexting via Customer Service) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming the role of someone who works for Customer Service, to solicit information
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-412-pretexting-via-customer-service
CAPEC-413 - MITRE CAPEC-413: Pretexting via Tech Support (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-413 (Pretexting via Tech Support) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming the role of a tech support worker, to solicit information from target persons,
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-413-pretexting-via-tech-support
CAPEC-414 - MITRE CAPEC-414: Pretexting via Delivery Person (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-414 (Pretexting via Delivery Person) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming the role of a delivery person, to solicit information from target persons,
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-414-pretexting-via-delivery-person
CAPEC-415 - MITRE CAPEC-415: Pretexting via Phone (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-415 (Pretexting via Phone) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in pretexting behavior, assuming some sort of trusted role, and contacting the targeted individual or organization via
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-415-pretexting-via-phone
CAPEC-416 - MITRE CAPEC-416: Manipulate Human Behavior (Meta Attack Pattern - Medium Severity)
MITRE CAPEC-416 (Manipulate Human Behavior) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits inherent human psychological predisposition to influence a targeted individual or group to solicit information or ma
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-416-manipulate-human-behavior
CAPEC-417 - MITRE CAPEC-417: Influence Perception (Standard Attack Pattern - Low Severity)
MITRE CAPEC-417 (Influence Perception) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary uses social engineering to exploit the target's perception of the relationship between the adversary and themselves. This goa
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-417-influence-perception
CAPEC-418 - MITRE CAPEC-418: Influence Perception of Reciprocation (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-418 (Influence Perception of Reciprocation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a social engineering techniques to produce a sense of obligation in the target to perform a certain acti
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-418-influence-perception-of-reciprocation
CAPEC-420 - MITRE CAPEC-420: Influence Perception of Scarcity (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-420 (Influence Perception of Scarcity) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary leverages a perception of scarcity to persuade the target to perform an action or divulge information that is adv
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-420-influence-perception-of-scarcity
CAPEC-421 - MITRE CAPEC-421: Influence Perception of Authority (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-421 (Influence Perception of Authority) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses a social engineering technique to convey a sense of authority that motivates the target to reveal specific i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-421-influence-perception-of-authority
CAPEC-422 - MITRE CAPEC-422: Influence Perception of Commitment and Consistency (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-422 (Influence Perception of Commitment and Consistency) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses social engineering to convince the target to do minor tasks as opposed to larger actions. A
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-422-influence-perception-of-commitment-and-consistency
CAPEC-423 - MITRE CAPEC-423: Influence Perception of Liking (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-423 (Influence Perception of Liking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary influences the target's actions by building a relationship where the target has a liking to the adversary. People a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-423-influence-perception-of-liking
CAPEC-424 - MITRE CAPEC-424: Influence Perception of Consensus or Social Proof (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-424 (Influence Perception of Consensus or Social Proof) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary influences the target's actions by leveraging the inherent human nature to assume behavior of ot
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-424-influence-perception-of-consensus-or-social-proof
CAPEC-425 - MITRE CAPEC-425: Target Influence via Framing (Standard Attack Pattern - Low Severity)
MITRE CAPEC-425 (Target Influence via Framing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses framing techniques to contextualize a conversation so that the target is more likely to be influenced by the adve
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-425-target-influence-via-framing
CAPEC-426 - MITRE CAPEC-426: Influence via Incentives (Standard Attack Pattern - Low Severity)
MITRE CAPEC-426 (Influence via Incentives) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary incites a behavior from the target by manipulating something of influence. This is commonly associated with financial, so
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-426-influence-via-incentives
CAPEC-427 - MITRE CAPEC-427: Influence via Psychological Principles (Standard Attack Pattern - Low Severity)
MITRE CAPEC-427 (Influence via Psychological Principles) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary shapes the target's actions or behavior by focusing on the ways human interact and learn, leveraging such e
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-427-influence-via-psychological-principles
CAPEC-428 - MITRE CAPEC-428: Influence via Modes of Thinking (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-428 (Influence via Modes of Thinking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary tailors their communication to the language and thought patterns of the target thereby weakening barriers or reluc
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-428-influence-via-modes-of-thinking
CAPEC-429 - MITRE CAPEC-429: Target Influence via Eye Cues (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-429 (Target Influence via Eye Cues) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary gains information via non-verbal means from the target through eye movements. Typical severity: Low. Child of CAPEC-
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-429-target-influence-via-eye-cues
CAPEC-433 - MITRE CAPEC-433: Target Influence via The Human Buffer Overflow (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-433 (Target Influence via The Human Buffer Overflow) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker utilizes a technique to insinuate commands to the subconscious mind of the target via communication p
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-433-target-influence-via-the-human-buffer-overflow
CAPEC-434 - MITRE CAPEC-434: Target Influence via Interview and Interrogation (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-434 (Target Influence via Interview and Interrogation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Typical severity: Low. Child of CAPEC-427.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-434-target-influence-via-interview-and-interrogation
CAPEC-435 - MITRE CAPEC-435: Target Influence via Instant Rapport (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-435 (Target Influence via Instant Rapport) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Typical severity: Low. Child of CAPEC-427.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-435-target-influence-via-instant-rapport
CAPEC-438 - MITRE CAPEC-438: Modification During Manufacture (Meta Attack Pattern)
MITRE CAPEC-438 (Modification During Manufacture) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker modifies a technology, product, or component during a stage in its manufacture for the purpose of carrying out an attack
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-438-modification-during-manufacture
CAPEC-439 - MITRE CAPEC-439: Manipulation During Distribution (Meta Attack Pattern)
MITRE CAPEC-439 (Manipulation During Distribution) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker undermines the integrity of a product, software, or technology at some stage of the distribution channel. The core thre
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-439-manipulation-during-distribution
CAPEC-440 - MITRE CAPEC-440: Hardware Integrity Attack (Meta Attack Pattern - High Severity)
MITRE CAPEC-440 (Hardware Integrity Attack) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in the system maintenance process and causes a change to be made to a technology, product, component, or
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-440-hardware-integrity-attack
CAPEC-441 - MITRE CAPEC-441: Malicious Logic Insertion (Attack Pattern - High Severity, Supply Chain)
MITRE CAPEC-441 (Malicious Logic Insertion) is an attack pattern in which an adversary installs or adds malicious logic (malware) into a seemingly benign component of a fielded system. Targets already-deployed systems exploiting wireless and Bluetooth vectors. Likelihood: Medium.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-441-malicious-logic-insertion
CAPEC-442 - MITRE CAPEC-442: Infected Software (Standard Attack Pattern - High Severity)
MITRE CAPEC-442 (Infected Software) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds malicious logic, often in the form of a computer virus, to otherwise benign software. This logic is often hidden from the us
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-442-infected-software
CAPEC-443 - MITRE CAPEC-443: Malicious Logic Inserted Into Product by Authorized Developer (Detailed Attack Pattern - High Severity)
MITRE CAPEC-443 (Malicious Logic Inserted Into Product by Authorized Developer) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses their privileged position within an authorized development organization to injec
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-443-malicious-logic-inserted-into-product-by-authorized-develope
CAPEC-444 - MITRE CAPEC-444: Development Alteration (Standard Attack Pattern - High Severity)
MITRE CAPEC-444 (Development Alteration) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary modifies a technology, product, or component during its development to acheive a negative impact once the system is deployed
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-444-development-alteration
CAPEC-445 - MITRE CAPEC-445: Malicious Logic Insertion into Product Software via Configuration Management Manipulation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-445 (Malicious Logic Insertion into Product Software via Configuration Management Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a configuration management system so that malici
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-445-malicious-logic-insertion-into-product-software-via-configur
CAPEC-446 - MITRE CAPEC-446: Malicious Logic Insertion into Product via Inclusion of Third-Party Component (Detailed Attack Pattern - High Severity)
MITRE CAPEC-446 (Malicious Logic Insertion into Product via Inclusion of Third-Party Component) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary conducts supply chain attacks by the inclusion of insecure third-part
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-446-malicious-logic-insertion-into-product-via-inclusion-of
CAPEC-447 - MITRE CAPEC-447: Design Alteration (Standard Attack Pattern - High Severity)
MITRE CAPEC-447 (Design Alteration) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary modifies the design of a technology, product, or component to acheive a negative impact once the system is deployed. In this type
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-447-design-alteration
CAPEC-448 - MITRE CAPEC-448: Embed Virus into DLL (Detailed Attack Pattern - High Severity)
MITRE CAPEC-448 (Embed Virus into DLL) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary tampers with a DLL and embeds a computer virus into gaps between legitimate machine instructions. These gaps may be the result
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-448-embed-virus-into-dll
CAPEC-452 - MITRE CAPEC-452: Infected Hardware (Standard Attack Pattern - High Severity)
MITRE CAPEC-452 (Infected Hardware) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts malicious logic into hardware, typically in the form of a computer virus or rootkit. This logic is often hidden from the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-452-infected-hardware
CAPEC-456 - MITRE CAPEC-456: Infected Memory (Standard Attack Pattern - High Severity)
MITRE CAPEC-456 (Infected Memory) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts malicious logic into memory enabling them to achieve a negative impact. This logic is often hidden from the user of the sys
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-456-infected-memory
CAPEC-457 - MITRE CAPEC-457: USB Memory Attacks (Detailed Attack Pattern - High Severity)
MITRE CAPEC-457 (USB Memory Attacks) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary loads malicious code onto a USB memory stick in order to infect any system which the device is plugged in to. USB drives present
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-457-usb-memory-attacks
CAPEC-458 - MITRE CAPEC-458: Flash Memory Attacks (Detailed Attack Pattern)
MITRE CAPEC-458 (Flash Memory Attacks) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts malicious logic into a product or technology via flashing the on-board memory with a code-base that contains malicious
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-458-flash-memory-attacks
CAPEC-459 - MITRE CAPEC-459: Creating a Rogue Certification Authority Certificate (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-459 (Creating a Rogue Certification Authority Certificate) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness resulting from using a hashing algorithm with weak collision resistance to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-459-creating-a-rogue-certification-authority-certificate
CAPEC-460 - MITRE CAPEC-460: HTTP Parameter Pollution (HPP) (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-460 (HTTP Parameter Pollution (HPP)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-460-http-parameter-pollution-hpp
CAPEC-461 - MITRE CAPEC-461: Web Services API Signature Forgery Leveraging Hash Function Extension Weakness (Standard Attack Pattern - High Severity)
MITRE CAPEC-461 (Web Services API Signature Forgery Leveraging Hash Function Extension Weakness) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary utilizes a hash function extension/padding weakness, to modify the p
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-461-web-services-api-signature-forgery-leveraging-hash-function
CAPEC-462 - MITRE CAPEC-462: Cross-Domain Search Timing (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-462 (Cross-Domain Search Timing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker initiates cross domain HTTP / GET requests and times the server responses. The timing of these responses may leak importa
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-462-cross-domain-search-timing
CAPEC-463 - MITRE CAPEC-463: Padding Oracle Crypto Attack (Detailed Attack Pattern - High Severity)
MITRE CAPEC-463 (Padding Oracle Crypto Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-463-padding-oracle-crypto-attack
CAPEC-464 - MITRE CAPEC-464: Evercookie (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-464 (Evercookie) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker creates a very persistent cookie that stays present even after the user thinks it has been removed. The cookie is stored on the victim's
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-464-evercookie
CAPEC-465 - MITRE CAPEC-465: Transparent Proxy Abuse (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-465 (Transparent Proxy Abuse) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A transparent proxy serves as an intermediate between the client and the internet at large. It intercepts all requests originating from
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-465-transparent-proxy-abuse
CAPEC-466 - MITRE CAPEC-466: Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-466 (Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages an adversary in the middle attack (CAPEC-94) in order to by
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-466-leveraging-active-adversary-in-the-middle-attacks-to
CAPEC-467 - MITRE CAPEC-467: Cross Site Identification (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-467 (Cross Site Identification) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker harvests identifying information about a victim via an active session that the victim's browser has with a social networki
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-467-cross-site-identification
CAPEC-468 - MITRE CAPEC-468: Generic Cross-Browser Cross-Domain Theft (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-468 (Generic Cross-Browser Cross-Domain Theft) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker makes use of Cascading Style Sheets (CSS) injection to steal data cross domain from the victim's browser. T
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-468-generic-cross-browser-cross-domain-theft
CAPEC-469 - MITRE CAPEC-469: HTTP DoS (Standard Attack Pattern - Low Severity)
MITRE CAPEC-469 (HTTP DoS) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker performs flooding at the HTTP level to bring down only a particular web application rather than anything listening on a TCP/IP connection.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-469-http-dos
CAPEC-470 - MITRE CAPEC-470: Expanding Control over the Operating System from the Database (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-470 (Expanding Control over the Operating System from the Database) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker is able to leverage access gained to the database to read / write data to the file sys
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-470-expanding-control-over-the-operating-system-from-the
CAPEC-471 - MITRE CAPEC-471: Search Order Hijacking (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-471 (Search Order Hijacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in an application's specification of external libraries to exploit the functionality of the loader where
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-471-search-order-hijacking
CAPEC-472 - MITRE CAPEC-472: Browser Fingerprinting (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-472 (Browser Fingerprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker carefully crafts small snippets of Java Script to efficiently detect the type of browser the potential victim is using. Many
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-472-browser-fingerprinting
CAPEC-473 - MITRE CAPEC-473: Signature Spoof (Standard Attack Pattern)
MITRE CAPEC-473 (Signature Spoof) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker generates a message or datablock that causes the recipient to believe that the message or datablock was generated and cryptographica
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-473-signature-spoof
CAPEC-474 - MITRE CAPEC-474: Signature Spoofing by Key Theft (Detailed Attack Pattern - High Severity)
MITRE CAPEC-474 (Signature Spoofing by Key Theft) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to forge signat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-474-signature-spoofing-by-key-theft
CAPEC-475 - MITRE CAPEC-475: Signature Spoofing by Improper Validation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-475 (Signature Spoofing by Improper Validation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a va
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-475-signature-spoofing-by-improper-validation
CAPEC-476 - MITRE CAPEC-476: Signature Spoofing by Misrepresentation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-476 (Signature Spoofing by Misrepresentation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in the parsing or display code of the recipient software to generate a data blob contain
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-476-signature-spoofing-by-misrepresentation
CAPEC-477 - MITRE CAPEC-477: Signature Spoofing by Mixing Signed and Unsigned Content (Detailed Attack Pattern - High Severity)
MITRE CAPEC-477 (Signature Spoofing by Mixing Signed and Unsigned Content) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits the underlying complexity of a data structure that allows for both signed and unsi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-477-signature-spoofing-by-mixing-signed-and-unsigned-content
CAPEC-478 - MITRE CAPEC-478: Modification of Windows Service Configuration (Detailed Attack Pattern - High Severity)
MITRE CAPEC-478 (Modification of Windows Service Configuration) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in access control to modify the execution parameters of a Windows service. The go
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-478-modification-of-windows-service-configuration
CAPEC-479 - MITRE CAPEC-479: Malicious Root Certificate (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-479 (Malicious Root Certificate) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authorization and installs a new root certificate on a compromised system. Certificates are commo
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-479-malicious-root-certificate
CAPEC-480 - MITRE CAPEC-480: Escaping Virtualization (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-480 (Escaping Virtualization) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gains access to an application, service, or device with the privileges of an authorized or privileged user by escaping the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-480-escaping-virtualization
CAPEC-481 - MITRE CAPEC-481: Contradictory Destinations in Traffic Routing Schemes (Standard Attack Pattern - High Severity)
MITRE CAPEC-481 (Contradictory Destinations in Traffic Routing Schemes) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries can provide contradictory destinations when sending messages. Traffic is routed in networks us
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-481-contradictory-destinations-in-traffic-routing-schemes
CAPEC-482 - MITRE CAPEC-482: TCP Flood (Standard Attack Pattern)
MITRE CAPEC-482 (TCP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the TCP protocol with the intent to deny legitimate users access to a service. These attacks exploit
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-482-tcp-flood
CAPEC-485 - MITRE CAPEC-485: Signature Spoofing by Key Recreation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-485 (Signature Spoofing by Key Recreation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-485-signature-spoofing-by-key-recreation
CAPEC-486 - MITRE CAPEC-486: UDP Flood (Standard Attack Pattern)
MITRE CAPEC-486 (UDP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the UDP protocol with the intent to deny legitimate users access to a service by consuming the availa
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-486-udp-flood
CAPEC-487 - MITRE CAPEC-487: ICMP Flood (Standard Attack Pattern)
MITRE CAPEC-487 (ICMP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the ICMP protocol with the intent to deny legitimate users access to a service by consuming the avai
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-487-icmp-flood
CAPEC-488 - MITRE CAPEC-488: HTTP Flood (Standard Attack Pattern)
MITRE CAPEC-488 (HTTP Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the HTTP protocol with the intent to deny legitimate users access to a service by consuming resource
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-488-http-flood
CAPEC-489 - MITRE CAPEC-489: SSL Flood (Standard Attack Pattern)
MITRE CAPEC-489 (SSL Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using the SSL protocol with the intent to deny legitimate users access to a service by consuming all the av
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-489-ssl-flood
CAPEC-490 - MITRE CAPEC-490: Amplification (Standard Attack Pattern)
MITRE CAPEC-490 (Amplification) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute an amplification where the size of a response is far greater than that of the request that generates it. The goal of this
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-490-amplification
CAPEC-491 - MITRE CAPEC-491: Quadratic Data Expansion (Detailed Attack Pattern)
MITRE CAPEC-491 (Quadratic Data Expansion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits macro-like substitution to cause a denial of service situation due to excessive memory being allocated to fully e
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-491-quadratic-data-expansion
CAPEC-492 - MITRE CAPEC-492: Regular Expression Exponential Blowup (Standard Attack Pattern)
MITRE CAPEC-492 (Regular Expression Exponential Blowup) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute an attack on a program that uses a poor Regular Expression(Regex) implementation by choosing inpu
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-492-regular-expression-exponential-blowup
CAPEC-493 - MITRE CAPEC-493: SOAP Array Blowup (Standard Attack Pattern)
MITRE CAPEC-493 (SOAP Array Blowup) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute an attack on a web service that uses SOAP messages in communication. By sending a very large SOAP array declaration t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-493-soap-array-blowup
CAPEC-494 - MITRE CAPEC-494: TCP Fragmentation (Standard Attack Pattern)
MITRE CAPEC-494 (TCP Fragmentation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a TCP Fragmentation attack against a target with the intention of avoiding filtering rules of network controls, by at
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-494-tcp-fragmentation
CAPEC-495 - MITRE CAPEC-495: UDP Fragmentation (Standard Attack Pattern)
MITRE CAPEC-495 (UDP Fragmentation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may execute a UDP Fragmentation attack against a target server in an attempt to consume resources such as bandwidth and CPU. IP fr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-495-udp-fragmentation
CAPEC-496 - MITRE CAPEC-496: ICMP Fragmentation (Standard Attack Pattern)
MITRE CAPEC-496 (ICMP Fragmentation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may execute a ICMP Fragmentation attack against a target with the intention of consuming resources or causing a crash. The attack
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-496-icmp-fragmentation
CAPEC-497 - MITRE CAPEC-497: File Discovery (Standard Attack Pattern - Very Low Severity)
MITRE CAPEC-497 (File Discovery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in probing and exploration activities to determine if common key files exists. Such files often contain configuration and se
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-497-file-discovery
CAPEC-498 - MITRE CAPEC-498: Probe iOS Screenshots (Detailed Attack Pattern)
MITRE CAPEC-498 (Probe iOS Screenshots) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary examines screenshot images created by iOS in an attempt to obtain sensitive information. This attack targets temporary screen
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-498-probe-ios-screenshots
CAPEC-499 - MITRE CAPEC-499: Android Intent Intercept (Standard Attack Pattern)
MITRE CAPEC-499 (Android Intent Intercept) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, intercepts messages from a trusted Android-based application in an
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-499-android-intent-intercept
CAPEC-500 - MITRE CAPEC-500: WebView Injection (Detailed Attack Pattern)
MITRE CAPEC-500 (WebView Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, injects code into the context of a web page displayed by a WebView compone
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-500-webview-injection
CAPEC-501 - MITRE CAPEC-501: Android Activity Hijack (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-501 (Android Activity Hijack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary intercepts an implicit intent sent to launch a Android-based trusted activity and instead launches a counterfeit activity i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-501-android-activity-hijack
CAPEC-502 - MITRE CAPEC-502: Intent Spoof (Standard Attack Pattern)
MITRE CAPEC-502 (Intent Spoof) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, issues an intent directed toward a specific trusted application's component in
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-502-intent-spoof
CAPEC-503 - MITRE CAPEC-503: WebView Exposure (Standard Attack Pattern)
MITRE CAPEC-503 (WebView Exposure) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a malicious web page, accesses application specific functionality by leveraging interfaces registered through WebView's a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-503-webview-exposure
CAPEC-504 - MITRE CAPEC-504: Task Impersonation (Standard Attack Pattern - High Severity)
MITRE CAPEC-504 (Task Impersonation) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, impersonates an expected or routine task in an attempt to steal sensitive
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-504-task-impersonation
CAPEC-505 - MITRE CAPEC-505: Scheme Squatting (Detailed Attack Pattern)
MITRE CAPEC-505 (Scheme Squatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, registers for a URL scheme intended for a target application that has not b
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-505-scheme-squatting
CAPEC-506 - MITRE CAPEC-506: Tapjacking (Standard Attack Pattern - Low Severity)
MITRE CAPEC-506 (Tapjacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, displays an interface that misleads the user and convinces them to tap on an atta
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-506-tapjacking
CAPEC-507 - MITRE CAPEC-507: Physical Theft (Meta Attack Pattern)
MITRE CAPEC-507 (Physical Theft) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gains physical access to a system or device through theft of the item. Possession of a system or device enables a number of unique attac
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-507-physical-theft
CAPEC-508 - MITRE CAPEC-508: Shoulder Surfing (Detailed Attack Pattern - High Severity)
MITRE CAPEC-508 (Shoulder Surfing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In a shoulder surfing attack, an adversary observes an unaware individual's keystrokes, screen content, or conversations with the goal of obtai
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-508-shoulder-surfing
CAPEC-509 - MITRE CAPEC-509: Kerberoasting (Detailed Attack Pattern - High Severity)
MITRE CAPEC-509 (Kerberoasting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Through the exploitation of how service accounts leverage Kerberos authentication with Service Principal Names (SPNs), the adversary obtains and s
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-509-kerberoasting
CAPEC-510 - MITRE CAPEC-510: SaaS User Request Forgery (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-510 (SaaS User Request Forgery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, performs malicious actions against a third-party Software as a Ser
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-510-saas-user-request-forgery
CAPEC-511 - MITRE CAPEC-511: Infiltration of Software Development Environment (Detailed Attack Pattern - High Severity)
MITRE CAPEC-511 (Infiltration of Software Development Environment) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses common delivery mechanisms such as email attachments or removable media to infiltrate the IDE
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-511-infiltration-of-software-development-environment
CAPEC-516 - MITRE CAPEC-516: Hardware Component Substitution During Baselining (Detailed Attack Pattern - High Severity)
MITRE CAPEC-516 (Hardware Component Substitution During Baselining) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to system components during allocated baseline development can substitute a malicious
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-516-hardware-component-substitution-during-baselining
CAPEC-517 - MITRE CAPEC-517: Documentation Alteration to Circumvent Dial-down (Detailed Attack Pattern - High Severity)
MITRE CAPEC-517 (Documentation Alteration to Circumvent Dial-down) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's documentation, which include descriptions of advanced technology an
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-517-documentation-alteration-to-circumvent-dial-down
CAPEC-518 - MITRE CAPEC-518: Documentation Alteration to Produce Under-performing Systems (Detailed Attack Pattern - High Severity)
MITRE CAPEC-518 (Documentation Alteration to Produce Under-performing Systems) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's documentation alters the descriptions of system capabil
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-518-documentation-alteration-to-produce-under-performing-systems
CAPEC-519 - MITRE CAPEC-519: Documentation Alteration to Cause Errors in System Design (Detailed Attack Pattern - High Severity)
MITRE CAPEC-519 (Documentation Alteration to Cause Errors in System Design) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's documentation containing requirements allocation and softw
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-519-documentation-alteration-to-cause-errors-in-system-design
CAPEC-520 - MITRE CAPEC-520: Counterfeit Hardware Component Inserted During Product Assembly (Detailed Attack Pattern - High Severity)
MITRE CAPEC-520 (Counterfeit Hardware Component Inserted During Product Assembly) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with either direct access to the product assembly process or to the supply of subco
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-520-counterfeit-hardware-component-inserted-during-product-assem
CAPEC-521 - MITRE CAPEC-521: Hardware Design Specifications Are Altered (Detailed Attack Pattern - High Severity)
MITRE CAPEC-521 (Hardware Design Specifications Are Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to a manufacturer's hardware manufacturing process documentation alters the design specificat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-521-hardware-design-specifications-are-altered
CAPEC-522 - MITRE CAPEC-522: Malicious Hardware Component Replacement (Standard Attack Pattern - High Severity)
MITRE CAPEC-522 (Malicious Hardware Component Replacement) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary replaces legitimate hardware in the system with faulty counterfeit or tampered hardware in the supply chai
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-522-malicious-hardware-component-replacement
CAPEC-523 - MITRE CAPEC-523: Malicious Software Implanted (Standard Attack Pattern - High Severity)
MITRE CAPEC-523 (Malicious Software Implanted) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker implants malicious software into the system in the supply chain distribution channel, with purpose of causing malicious
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-523-malicious-software-implanted
CAPEC-524 - MITRE CAPEC-524: Rogue Integration Procedures (Standard Attack Pattern - High Severity)
MITRE CAPEC-524 (Rogue Integration Procedures) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker alters or establishes rogue processes in an integration facility in order to insert maliciously altered components into
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-524-rogue-integration-procedures
CAPEC-528 - MITRE CAPEC-528: XML Flood (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-528 (XML Flood) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may execute a flooding attack using XML messages with the intent to deny legitimate users access to a web service. These attacks are acco
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-528-xml-flood
CAPEC-529 - MITRE CAPEC-529: Malware-Directed Internal Reconnaissance (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-529 (Malware-Directed Internal Reconnaissance) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversary uses malware or a similarly controlled application installed inside an organizational perimeter to gather inf
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-529-malware-directed-internal-reconnaissance
CAPEC-530 - MITRE CAPEC-530: Provide Counterfeit Component (Detailed Attack Pattern - High Severity)
MITRE CAPEC-530 (Provide Counterfeit Component) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker provides a counterfeit component during the procurement process of a lower-tier component supplier to a sub-system dev
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-530-provide-counterfeit-component
CAPEC-531 - MITRE CAPEC-531: Hardware Component Substitution (Detailed Attack Pattern - High Severity)
MITRE CAPEC-531 (Hardware Component Substitution) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker substitutes out a tested and approved hardware component for a maliciously-altered hardware component. This type of
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-531-hardware-component-substitution
CAPEC-532 - MITRE CAPEC-532: Altered Installed BIOS (Detailed Attack Pattern - High Severity)
MITRE CAPEC-532 (Altered Installed BIOS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to download and update system software sends a maliciously altered BIOS to the victim or victim supplier/integrat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-532-altered-installed-bios
CAPEC-533 - MITRE CAPEC-533: Malicious Manual Software Update (Detailed Attack Pattern - High Severity)
MITRE CAPEC-533 (Malicious Manual Software Update) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker introduces malicious code to the victim's system by altering the payload of a software update, allowing for additio
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-533-malicious-manual-software-update
CAPEC-534 - MITRE CAPEC-534: Malicious Hardware Update (Standard Attack Pattern - High Severity)
MITRE CAPEC-534 (Malicious Hardware Update) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary introduces malicious hardware during an update or replacement procedure, allowing for additional compromise or site disru
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-534-malicious-hardware-update
CAPEC-535 - MITRE CAPEC-535: Malicious Gray Market Hardware (Detailed Attack Pattern - High Severity)
MITRE CAPEC-535 (Malicious Gray Market Hardware) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker maliciously alters hardware components that will be sold on the gray market, allowing for victim disruption and compr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-535-malicious-gray-market-hardware
CAPEC-536 - MITRE CAPEC-536: Data Injected During Configuration (Standard Attack Pattern - High Severity)
MITRE CAPEC-536 (Data Injected During Configuration) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to data files and processes on a victim's system injects malicious data into critical operational dat
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-536-data-injected-during-configuration
CAPEC-537 - MITRE CAPEC-537: Infiltration of Hardware Development Environment (Detailed Attack Pattern - High Severity)
MITRE CAPEC-537 (Infiltration of Hardware Development Environment) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, leveraging the ability to manipulate components of primary support systems and tools within the d
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-537-infiltration-of-hardware-development-environment
CAPEC-538 - MITRE CAPEC-538: Open-Source Library Manipulation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-538 (Open-Source Library Manipulation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries implant malicious code in open source software (OSS) libraries to have it widely distributed, as OSS is commonly do
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-538-open-source-library-manipulation
CAPEC-539 - MITRE CAPEC-539: ASIC With Malicious Functionality (Detailed Attack Pattern - High Severity)
MITRE CAPEC-539 (ASIC With Malicious Functionality) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker with access to the development environment process of an application-specific integrated circuit (ASIC) for a vict
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-539-asic-with-malicious-functionality
CAPEC-540 - MITRE CAPEC-540: Overread Buffers (Standard Attack Pattern - High Severity)
MITRE CAPEC-540 (Overread Buffers) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occ
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-540-overread-buffers
CAPEC-541 - MITRE CAPEC-541: Application Fingerprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-541 (Application Fingerprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in fingerprinting activities to determine the type or version of an application installed on a remote target. Li
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-541-application-fingerprinting
CAPEC-542 - MITRE CAPEC-542: Targeted Malware (Standard Attack Pattern)
MITRE CAPEC-542 (Targeted Malware) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary develops targeted malware that takes advantage of a known vulnerability in an organizational information technology environment. T
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-542-targeted-malware
CAPEC-543 - MITRE CAPEC-543: Counterfeit Websites (Detailed Attack Pattern - High Severity)
MITRE CAPEC-543 (Counterfeit Websites) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversary creates duplicates of legitimate websites. When users visit a counterfeit site, the site can gather information or upload malware
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-543-counterfeit-websites
CAPEC-544 - MITRE CAPEC-544: Counterfeit Organizations (Detailed Attack Pattern - High Severity)
MITRE CAPEC-544 (Counterfeit Organizations) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary creates a false front organizations with the appearance of a legitimate supplier in the critical life cycle path that the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-544-counterfeit-organizations
CAPEC-545 - MITRE CAPEC-545: Pull Data from System Resources (Standard Attack Pattern)
MITRE CAPEC-545 (Pull Data from System Resources) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary who is authorized or has the ability to search known system resources, does so with the intention of gathering usef
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-545-pull-data-from-system-resources
CAPEC-546 - MITRE CAPEC-546: Incomplete Data Deletion in a Multi-Tenant Environment (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-546 (Incomplete Data Deletion in a Multi-Tenant Environment) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains unauthorized information due to insecure or incomplete data deletion in a multi-tena
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-546-incomplete-data-deletion-in-a-multi-tenant-environment
CAPEC-547 - MITRE CAPEC-547: Physical Destruction of Device or Component (Standard Attack Pattern - Unrated Severity)
MITRE CAPEC-547 (Physical Destruction of Device or Component) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary conducts a physical attack a device or component, destroying it such that it no longer functions as int
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-547-physical-destruction-of-device-or-component
CAPEC-548 - MITRE CAPEC-548: Contaminate Resource (Meta Attack Pattern - High Severity)
MITRE CAPEC-548 (Contaminate Resource) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary contaminates organizational information systems (including devices and networks) by causing them to handle information of a classi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-548-contaminate-resource
CAPEC-549 - MITRE CAPEC-549: Local Execution of Code (Meta Attack Pattern - High Severity)
MITRE CAPEC-549 (Local Execution of Code) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary installs and executes malicious code on the target system in an effort to achieve a negative technical impact. Examples include
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-549-local-execution-of-code
CAPEC-550 - MITRE CAPEC-550: Install New Service (Detailed Attack Pattern)
MITRE CAPEC-550 (Install New Service) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. When an operating system starts, it also starts programs called services or daemons. Adversaries may install a new service which will be exe
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-550-install-new-service
CAPEC-551 - MITRE CAPEC-551: Modify Existing Service (Detailed Attack Pattern)
MITRE CAPEC-551 (Modify Existing Service) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. When an operating system starts, it also starts programs called services or daemons. Modifying existing services may break existing serv
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-551-modify-existing-service
CAPEC-552 - MITRE CAPEC-552: Install Rootkit (Detailed Attack Pattern - High Severity)
MITRE CAPEC-552 (Install Rootkit) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authentication to install malware that alters the functionality and information provide by targeted operatin
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-552-install-rootkit
CAPEC-554 - MITRE CAPEC-554: Functionality Bypass (Meta Attack Pattern - High Severity)
MITRE CAPEC-554 (Functionality Bypass) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attacks a system by bypassing some or all functionality intended to protect it. Often, a system user will think that protection is
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-554-functionality-bypass
CAPEC-555 - MITRE CAPEC-555: Remote Services with Stolen Credentials (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-555 (Remote Services with Stolen Credentials) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This pattern of attack involves an adversary that uses stolen credentials to leverage remote services such as RDP, telne
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-555-remote-services-with-stolen-credentials
CAPEC-556 - MITRE CAPEC-556: Replace File Extension Handlers (Detailed Attack Pattern)
MITRE CAPEC-556 (Replace File Extension Handlers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. When a file is opened, its file handler is checked to determine which program opens the file. File handlers are configuration pr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-556-replace-file-extension-handlers
CAPEC-558 - MITRE CAPEC-558: Replace Trusted Executable (Detailed Attack Pattern - High Severity)
MITRE CAPEC-558 (Replace Trusted Executable) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits weaknesses in privilege management or access control to replace a trusted executable with a malicious version a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-558-replace-trusted-executable
CAPEC-559 - MITRE CAPEC-559: Orbital Jamming (Detailed Attack Pattern - High Severity)
MITRE CAPEC-559 (Orbital Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary sends disruptive signals at a target satellite using a rogue uplink station to disrupt the intended transm
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-559-orbital-jamming
CAPEC-560 - MITRE CAPEC-560: Use of Known Domain Credentials (Attack Pattern - High Severity)
MITRE CAPEC-560 (Use of Known Domain Credentials) is an attack pattern in which an adversary guesses or obtains (steals or purchases) legitimate credentials to achieve authentication and perform authorized actions under the guise of an authenticated user or service. Likelihood of
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-560-use-of-known-domain-credentials
CAPEC-561 - MITRE CAPEC-561: Windows Admin Shares with Stolen Credentials (Detailed Attack Pattern)
MITRE CAPEC-561 (Windows Admin Shares with Stolen Credentials) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary guesses or obtains (i.e. steals or purchases) legitimate Windows administrator credentials (e.g. userI
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-561-windows-admin-shares-with-stolen-credentials
CAPEC-562 - MITRE CAPEC-562: Modify Shared File (Detailed Attack Pattern)
MITRE CAPEC-562 (Modify Shared File) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary manipulates the files in a shared location by adding malicious programs, scripts, or exploit code to valid content. Once a user
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-562-modify-shared-file
CAPEC-563 - MITRE CAPEC-563: Add Malicious File to Shared Webroot (Detailed Attack Pattern)
MITRE CAPEC-563 (Add Malicious File to Shared Webroot) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversaries may add malicious content to a website through the open file share and then browse to that content with a we
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-563-add-malicious-file-to-shared-webroot
CAPEC-564 - MITRE CAPEC-564: Run Software at Logon (Detailed Attack Pattern)
MITRE CAPEC-564 (Run Software at Logon) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Operating system allows logon scripts to be run whenever a specific user or users logon to a system. If adversaries can access these scrip
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-564-run-software-at-logon
CAPEC-565 - MITRE CAPEC-565: Password Spraying (Detailed Attack Pattern - High Severity)
MITRE CAPEC-565 (Password Spraying) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In a Password Spraying attack, an adversary tries a small list (e.g. 3-5) of common or expected passwords, often matching the target's complex
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-565-password-spraying
CAPEC-568 - MITRE CAPEC-568: Capture Credentials via Keylogger (Detailed Attack Pattern - High Severity)
MITRE CAPEC-568 (Capture Credentials via Keylogger) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary deploys a keylogger in an effort to obtain credentials directly from a system's user. After capturing all the key
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-568-capture-credentials-via-keylogger
CAPEC-569 - MITRE CAPEC-569: Collect Data as Provided by Users (Standard Attack Pattern)
MITRE CAPEC-569 (Collect Data as Provided by Users) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages a tool, device, or program to obtain specific information as provided by a user of the target system. Th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-569-collect-data-as-provided-by-users
CAPEC-571 - MITRE CAPEC-571: Block Logging to Central Repository (Standard Attack Pattern - Low Severity)
MITRE CAPEC-571 (Block Logging to Central Repository) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary prevents host-generated logs being delivered to a central location in an attempt to hide indicators of compromi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-571-block-logging-to-central-repository
CAPEC-572 - MITRE CAPEC-572: Artificially Inflate File Sizes (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-572 (Artificially Inflate File Sizes) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary modifies file contents by adding data to files for several reasons. Many different attacks could "follow" this patt
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-572-artificially-inflate-file-sizes
CAPEC-573 - MITRE CAPEC-573: Process Footprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-573 (Process Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the currently running processes on the target system to an authoriz
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-573-process-footprinting
CAPEC-574 - MITRE CAPEC-574: Services Footprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-574 (Services Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the services on the target system to an authorized user. By knowin
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-574-services-footprinting
CAPEC-575 - MITRE CAPEC-575: Account Footprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-575 (Account Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the domain accounts and their permissions on the target system to a
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-575-account-footprinting
CAPEC-576 - MITRE CAPEC-576: Group Permission Footprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-576 (Group Permission Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about user groups and their permissions on the target system to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-576-group-permission-footprinting
CAPEC-577 - MITRE CAPEC-577: Owner Footprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-577 (Owner Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits functionality meant to identify information about the primary users on the target system to an authorized user. They ma
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-577-owner-footprinting
CAPEC-578 - MITRE CAPEC-578: Disable Security Software (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-578 (Disable Security Software) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in access control to disable security tools so that detection does not occur. This can take the form
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-578-disable-security-software
CAPEC-579 - MITRE CAPEC-579: Replace Winlogon Helper DLL (Detailed Attack Pattern)
MITRE CAPEC-579 (Replace Winlogon Helper DLL) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Winlogon is a part of Windows that performs logon actions. In Windows systems prior to Windows Vista, a registry key can be modified
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-579-replace-winlogon-helper-dll
CAPEC-580 - MITRE CAPEC-580: System Footprinting (Standard Attack Pattern - Low Severity)
MITRE CAPEC-580 (System Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary engages in active probing and exploration activities to determine security information about a remote target system. Often time
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-580-system-footprinting
CAPEC-581 - MITRE CAPEC-581: Security Software Footprinting (Detailed Attack Pattern)
MITRE CAPEC-581 (Security Software Footprinting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries may attempt to get a listing of security tools that are installed on the system and their configurations. This may in
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-581-security-software-footprinting
CAPEC-582 - MITRE CAPEC-582: Route Disabling (Standard Attack Pattern - High Severity)
MITRE CAPEC-582 (Route Disabling) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary disables the network route between two targets. The goal is to completely sever the communications channel between two entities. Th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-582-route-disabling
CAPEC-583 - MITRE CAPEC-583: Disabling Network Hardware (Detailed Attack Pattern)
MITRE CAPEC-583 (Disabling Network Hardware) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, an adversary physically disables networking hardware by powering it down or disconnecting critical equipment.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-583-disabling-network-hardware
CAPEC-584 - MITRE CAPEC-584: BGP Route Disabling (Detailed Attack Pattern)
MITRE CAPEC-584 (BGP Route Disabling) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary suppresses the Border Gateway Protocol (BGP) advertisement for a route so as to render the underlying network inaccessible. The
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-584-bgp-route-disabling
CAPEC-585 - MITRE CAPEC-585: DNS Domain Seizure (Detailed Attack Pattern)
MITRE CAPEC-585 (DNS Domain Seizure) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, an adversary influences a target's web-hosting company to disable a target domain. The goal is to prevent access to t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-585-dns-domain-seizure
CAPEC-586 - MITRE CAPEC-586: Object Injection (Meta Attack Pattern - High Severity)
MITRE CAPEC-586 (Object Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attempts to exploit an application by injecting additional, malicious content during its processing of serialized objects. Developers
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-586-object-injection
CAPEC-587 - MITRE CAPEC-587: Cross Frame Scripting (XFS) (Detailed Attack Pattern - High Severity)
MITRE CAPEC-587 (Cross Frame Scripting (XFS)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack pattern combines malicious Javascript and a legitimate webpage loaded into a concealed iframe. The malicious Javascript
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-587-cross-frame-scripting-xfs
CAPEC-588 - MITRE CAPEC-588: DOM-Based XSS (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-588 (DOM-Based XSS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is inserted into the client-side HTML being parsed by a web b
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-588-dom-based-xss
CAPEC-589 - MITRE CAPEC-589: DNS Blocking (Detailed Attack Pattern)
MITRE CAPEC-589 (DNS Blocking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary intercepts traffic and intentionally drops DNS requests based on content in the request. In this way, the adversary can deny the avail
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-589-dns-blocking
CAPEC-590 - MITRE CAPEC-590: IP Address Blocking (Detailed Attack Pattern - High Severity)
MITRE CAPEC-590 (IP Address Blocking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary performing this type of attack drops packets destined for a target IP address. The aim is to prevent access to the service host
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-590-ip-address-blocking
CAPEC-591 - MITRE CAPEC-591: Reflected XSS (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-591 (Reflected XSS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is "reflected" off a vulnerable web application and then exec
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-591-reflected-xss
CAPEC-592 - MITRE CAPEC-592: Stored XSS (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-592 (Stored XSS) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently "stored" within the data storage of a vulnerable
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-592-stored-xss
CAPEC-593 - MITRE CAPEC-593: Session Hijacking (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-593 (Session Hijacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adver
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-593-session-hijacking
CAPEC-594 - MITRE CAPEC-594: Traffic Injection (Meta Attack Pattern)
MITRE CAPEC-594 (Traffic Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary injects traffic into the target's network connection. The adversary is therefore able to degrade or disrupt the connection, and poten
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-594-traffic-injection
CAPEC-595 - MITRE CAPEC-595: Connection Reset (Standard Attack Pattern)
MITRE CAPEC-595 (Connection Reset) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, an adversary injects a connection reset packet to one or both ends of a target's connection. The attacker is therefore
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-595-connection-reset
CAPEC-596 - MITRE CAPEC-596: TCP RST Injection (Detailed Attack Pattern)
MITRE CAPEC-596 (TCP RST Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary injects one or more TCP RST packets to a target after the target has made a HTTP GET request. The goal of this attack is to have
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-596-tcp-rst-injection
CAPEC-597 - MITRE CAPEC-597: Absolute Path Traversal (Detailed Attack Pattern)
MITRE CAPEC-597 (Absolute Path Traversal) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to file system resources, either directly or via application logic, will use various file absolute paths and na
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-597-absolute-path-traversal
CAPEC-598 - MITRE CAPEC-598: DNS Spoofing (Detailed Attack Pattern)
MITRE CAPEC-598 (DNS Spoofing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a malicious ("NXDOMAIN" ("No such domain") code, or DNS A record) response to a target's route request before a legitimate resol
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-598-dns-spoofing
CAPEC-599 - MITRE CAPEC-599: Terrestrial Jamming (Detailed Attack Pattern - High Severity)
MITRE CAPEC-599 (Terrestrial Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack pattern, the adversary transmits disruptive signals in the direction of the target's consumer-level satellite dish (as oppose
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-599-terrestrial-jamming
CAPEC-600 - MITRE CAPEC-600: Credential Stuffing (Standard Attack Pattern - High Severity)
MITRE CAPEC-600 (Credential Stuffing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary tries known username/password combinations against different systems, applications, or services to gain additional authenticate
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-600-credential-stuffing
CAPEC-601 - MITRE CAPEC-601: Jamming (Standard Attack Pattern - High Severity)
MITRE CAPEC-601 (Jamming) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses radio noise or signals in an attempt to disrupt communications. By intentionally overwhelming system resources with illegitimate traff
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-601-jamming
CAPEC-603 - MITRE CAPEC-603: Blockage (Standard Attack Pattern - High Severity)
MITRE CAPEC-603 (Blockage) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary blocks the delivery of an important system resource causing the system to fail or stop working. Likelihood of attack: Medium. Typical seve
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-603-blockage
CAPEC-604 - MITRE CAPEC-604: Wi-Fi Jamming (Detailed Attack Pattern - High Severity)
MITRE CAPEC-604 (Wi-Fi Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker actively transmits on the Wi-Fi channel to prevent users from transmitting or receiving data from the target
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-604-wi-fi-jamming
CAPEC-605 - MITRE CAPEC-605: Cellular Jamming (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-605 (Cellular Jamming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker actively transmits signals to overpower and disrupt the communication between a cellular user device and
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-605-cellular-jamming
CAPEC-606 - MITRE CAPEC-606: Weakening of Cellular Encryption (Detailed Attack Pattern - High Severity)
MITRE CAPEC-606 (Weakening of Cellular Encryption) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker, with control of a Cellular Rogue Base Station or through cooperation with a Malicious Mobile Network Operator can
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-606-weakening-of-cellular-encryption
CAPEC-607 - MITRE CAPEC-607: Obstruction (Meta Attack Pattern - Unrated Severity)
MITRE CAPEC-607 (Obstruction) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker obstructs the interactions between system components. By interrupting or disabling these interactions, an adversary can often force the syst
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-607-obstruction
CAPEC-608 - MITRE CAPEC-608: Cryptanalysis of Cellular Encryption (Detailed Attack Pattern - High Severity)
MITRE CAPEC-608 (Cryptanalysis of Cellular Encryption) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The use of cryptanalytic techniques to derive cryptographic keys or otherwise effectively defeat cellular encryption to rev
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-608-cryptanalysis-of-cellular-encryption
CAPEC-609 - MITRE CAPEC-609: Cellular Traffic Intercept (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-609 (Cellular Traffic Intercept) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Cellular traffic for voice and data from mobile devices and retransmission devices can be intercepted via numerous methods. Malicious
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-609-cellular-traffic-intercept
CAPEC-610 - MITRE CAPEC-610: Cellular Data Injection (Standard Attack Pattern - High Severity)
MITRE CAPEC-610 (Cellular Data Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries inject data into mobile technology traffic (data flows or signaling data) to disrupt communications or conduct additional su
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-610-cellular-data-injection
CAPEC-611 - MITRE CAPEC-611: BitSquatting (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-611 (BitSquatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name one bit different than a trusted domain. A BitSquatting attack leverages random errors in memory to direct Int
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-611-bitsquatting
CAPEC-612 - MITRE CAPEC-612: WiFi MAC Address Tracking (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-612 (WiFi MAC Address Tracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively listens for WiFi messages and logs the associated Media Access Control (MAC) addresses
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-612-wifi-mac-address-tracking
CAPEC-613 - MITRE CAPEC-613: WiFi SSID Tracking (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-613 (WiFi SSID Tracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively listens for WiFi management frame messages containing the Service Set Identifier (SSID) for t
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-613-wifi-ssid-tracking
CAPEC-614 - MITRE CAPEC-614: Rooting SIM Cards (Detailed Attack Pattern - High Severity)
MITRE CAPEC-614 (Rooting SIM Cards) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. SIM cards are the de facto trust anchor of mobile devices worldwide. The cards protect the mobile identity of subscribers, associate devices w
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-614-rooting-sim-cards
CAPEC-615 - MITRE CAPEC-615: Evil Twin Wi-Fi Attack (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-615 (Evil Twin Wi-Fi Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries install Wi-Fi equipment that acts as a legitimate Wi-Fi network access point. When a device connects to this access point, Wi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-615-evil-twin-wi-fi-attack
CAPEC-616 - MITRE CAPEC-616: Establish Rogue Location (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-616 (Establish Rogue Location) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary provides a malicious version of a resource at a location that is similar to the expected location of a legitimate resource
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-616-establish-rogue-location
CAPEC-617 - MITRE CAPEC-617: Cellular Rogue Base Station (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-617 (Cellular Rogue Base Station) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker imitates a cellular base station with their own "rogue" base station equipment. Since cellular
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-617-cellular-rogue-base-station
CAPEC-618 - MITRE CAPEC-618: Cellular Broadcast Message Request (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-618 (Cellular Broadcast Message Request) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker uses knowledge of the target's mobile phone number (i.e., the number associated with th
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-618-cellular-broadcast-message-request
CAPEC-619 - MITRE CAPEC-619: Signal Strength Tracking (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-619 (Signal Strength Tracking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively monitors the signal strength of the target's cellular RF signal or WiFi RF signal and u
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-619-signal-strength-tracking
CAPEC-620 - MITRE CAPEC-620: Drop Encryption Level (Standard Attack Pattern - High Severity)
MITRE CAPEC-620 (Drop Encryption Level) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker forces the encryption level to be lowered, thus enabling a successful attack against the encrypted data. Likelihood of attack:
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-620-drop-encryption-level
CAPEC-621 - MITRE CAPEC-621: Analysis of Packet Timing and Sizes (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-621 (Analysis of Packet Timing and Sizes) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker may intercept and log encrypted transmissions for the purpose of analyzing metadata such as packet timing and si
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-621-analysis-of-packet-timing-and-sizes
CAPEC-622 - MITRE CAPEC-622: Electromagnetic Side-Channel Attack (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-622 (Electromagnetic Side-Channel Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. In this attack scenario, the attacker passively monitors electromagnetic emanations that are produced by the targeted electr
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-622-electromagnetic-side-channel-attack
CAPEC-623 - MITRE CAPEC-623: Compromising Emanations Attack (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-623 (Compromising Emanations Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Compromising Emanations (CE) are defined as unintentional signals which an attacker may intercept and analyze to disclose the inf
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-623-compromising-emanations-attack
CAPEC-624 - MITRE CAPEC-624: Hardware Fault Injection (Meta Attack Pattern - High Severity)
MITRE CAPEC-624 (Hardware Fault Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary uses disruptive signals or events, or alters the physical environment a device operates in, to cause faulty behavior in elect
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-624-hardware-fault-injection
CAPEC-625 - MITRE CAPEC-625: Mobile Device Fault Injection (Standard Attack Pattern)
MITRE CAPEC-625 (Mobile Device Fault Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Fault injection attacks against mobile devices use disruptive signals or events (e.g. electromagnetic pulses, laser pulses, clock
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-625-mobile-device-fault-injection
CAPEC-626 - MITRE CAPEC-626: Smudge Attack (Detailed Attack Pattern)
MITRE CAPEC-626 (Smudge Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Attacks that reveal the password/passcode pattern on a touchscreen device by detecting oil smudges left behind by the user's fingers. Likelihood o
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-626-smudge-attack
CAPEC-627 - MITRE CAPEC-627: Counterfeit GPS Signals (Standard Attack Pattern - High Severity)
MITRE CAPEC-627 (Counterfeit GPS Signals) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary attempts to deceive a GPS receiver by broadcasting counterfeit GPS signals, structured to resemble a set of normal GPS sign
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-627-counterfeit-gps-signals
CAPEC-628 - MITRE CAPEC-628: Carry-Off GPS Attack (Detailed Attack Pattern - High Severity)
MITRE CAPEC-628 (Carry-Off GPS Attack) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. A common form of a GPS spoofing attack, commonly termed a carry-off attack begins with an adversary broadcasting signals synchronized with
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-628-carry-off-gps-attack
CAPEC-630 - MITRE CAPEC-630: TypoSquatting (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-630 (TypoSquatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name with at least one character different than a trusted domain. A TypoSquatting attack takes advantage of instan
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-630-typosquatting
CAPEC-631 - MITRE CAPEC-631: SoundSquatting (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-631 (SoundSquatting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name that sounds the same as a trusted domain, but has a different spelling. A SoundSquatting attack takes advant
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-631-soundsquatting
CAPEC-632 - MITRE CAPEC-632: Homograph Attack via Homoglyphs (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-632 (Homograph Attack via Homoglyphs) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary registers a domain name containing a homoglyph, leading the registered domain to appear the same as a trusted domai
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-632-homograph-attack-via-homoglyphs
CAPEC-633 - MITRE CAPEC-633: Token Impersonation (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-633 (Token Impersonation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-633-token-impersonation
CAPEC-634 - MITRE CAPEC-634: Probe Audio and Video Peripherals (Detailed Attack Pattern - High Severity)
MITRE CAPEC-634 (Probe Audio and Video Peripherals) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary exploits the target system's audio and video functionalities through malware or scheduled tasks. The goal is to
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-634-probe-audio-and-video-peripherals
CAPEC-635 - MITRE CAPEC-635: Alternative Execution Due to Deceptive Filenames (Standard Attack Pattern - High Severity)
MITRE CAPEC-635 (Alternative Execution Due to Deceptive Filenames) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The extension of a file name is often used in various contexts to determine the application that is used to ope
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-635-alternative-execution-due-to-deceptive-filenames
CAPEC-636 - MITRE CAPEC-636: Hiding Malicious Data or Code within Files (Standard Attack Pattern - High Severity)
MITRE CAPEC-636 (Hiding Malicious Data or Code within Files) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Files on various operating systems can have a complex format which allows for the storage of other data, in addition
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-636-hiding-malicious-data-or-code-within-files
CAPEC-637 - MITRE CAPEC-637: Collect Data from Clipboard (Detailed Attack Pattern - Low Severity)
MITRE CAPEC-637 (Collect Data from Clipboard) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary exploits an application that allows for the copying of sensitive data or information by collecting information copied
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-637-collect-data-from-clipboard
CAPEC-638 - MITRE CAPEC-638: Altered Component Firmware (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-638 (Altered Component Firmware) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits systems features and/or improperly protected firmware of hardware components, such as Hard Disk Drives (HDD), w
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-638-altered-component-firmware
CAPEC-639 - MITRE CAPEC-639: Probe System Files (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-639 (Probe System Files) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains unauthorized information due to improperly protected files. If an application stores sensitive information in a file tha
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-639-probe-system-files
CAPEC-640 - MITRE CAPEC-640: Inclusion of Code in Existing Process (Detailed Attack Pattern - High Severity)
MITRE CAPEC-640 (Inclusion of Code in Existing Process) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The adversary takes advantage of a bug in an application failing to verify the integrity of the running process to execute
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-640-inclusion-of-code-in-existing-process
CAPEC-641 - MITRE CAPEC-641: DLL Side-Loading (Detailed Attack Pattern - High Severity)
MITRE CAPEC-641 (DLL Side-Loading) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary places a malicious version of a Dynamic-Link Library (DLL) in the Windows Side-by-Side (WinSxS) directory to trick the operating s
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-641-dll-side-loading
CAPEC-642 - MITRE CAPEC-642: Replace Binaries (Detailed Attack Pattern - High Severity)
MITRE CAPEC-642 (Replace Binaries) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries know that certain binaries will be regularly executed as part of normal processing. If these binaries are not protected with the ap
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-642-replace-binaries
CAPEC-643 - MITRE CAPEC-643: Identify Shared Files/Directories on System (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-643 (Identify Shared Files/Directories on System) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary discovers connections between systems by exploiting the target system's standard practice of revealing
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-643-identify-shared-files-directories-on-system
CAPEC-644 - MITRE CAPEC-644: Use of Captured Hashes (Pass The Hash) (Detailed Attack Pattern - High Severity)
MITRE CAPEC-644 (Use of Captured Hashes (Pass The Hash)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-644-use-of-captured-hashes-pass-the-hash
CAPEC-645 - MITRE CAPEC-645: Use of Captured Tickets (Pass The Ticket) (Detailed Attack Pattern - High Severity)
MITRE CAPEC-645 (Use of Captured Tickets (Pass The Ticket)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses stolen Kerberos tickets to access systems/resources that leverage the Kerberos authentication protoc
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-645-use-of-captured-tickets-pass-the-ticket
CAPEC-646 - MITRE CAPEC-646: Peripheral Footprinting (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-646 (Peripheral Footprinting) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Adversaries may attempt to obtain information about attached peripheral devices and components connected to a computer system. Examples
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-646-peripheral-footprinting
CAPEC-647 - MITRE CAPEC-647: Collect Data from Registries (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-647 (Collect Data from Registries) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authorization to gather system-specific data and sensitive information within a registry (e.g.,
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-647-collect-data-from-registries
CAPEC-648 - MITRE CAPEC-648: Collect Data from Screen Capture (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-648 (Collect Data from Screen Capture) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary gathers sensitive information by exploiting the system's screen capture functionality. Through screenshots, the ad
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-648-collect-data-from-screen-capture
CAPEC-649 - MITRE CAPEC-649: Adding a Space to a File Extension (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-649 (Adding a Space to a File Extension) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds a space character to the end of a file extension and takes advantage of an application that does not proper
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-649-adding-a-space-to-a-file-extension
CAPEC-650 - MITRE CAPEC-650: Upload a Web Shell to a Web Server (Detailed Attack Pattern - High Severity)
MITRE CAPEC-650 (Upload a Web Shell to a Web Server) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. By exploiting insufficient permissions, it is possible to upload a web shell to a web server in such a way that it can be exe
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-650-upload-a-web-shell-to-a-web-server
CAPEC-651 - MITRE CAPEC-651: Eavesdropping (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-651 (Eavesdropping) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary intercepts a form of communication (e.g. text, audio, video) by way of software (e.g., microphone and audio recording application), h
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-651-eavesdropping
CAPEC-652 - MITRE CAPEC-652: Use of Known Kerberos Credentials (Standard Attack Pattern - High Severity)
MITRE CAPEC-652 (Use of Known Kerberos Credentials) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-652-use-of-known-kerberos-credentials
CAPEC-653 - MITRE CAPEC-653: Use of Known Operating System Credentials (Standard Attack Pattern - High Severity)
MITRE CAPEC-653 (Use of Known Operating System Credentials) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary guesses or obtains (i.e. steals or purchases) legitimate operating system credentials (e.g. userID/passwo
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-653-use-of-known-operating-system-credentials
CAPEC-654 - MITRE CAPEC-654: Credential Prompt Impersonation (Detailed Attack Pattern - High Severity)
MITRE CAPEC-654 (Credential Prompt Impersonation) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary, through a previously installed malicious application, impersonates a credential prompt in an attempt to steal a us
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-654-credential-prompt-impersonation
CAPEC-655 - MITRE CAPEC-655: Avoid Security Tool Identification by Adding Data (Detailed Attack Pattern - High Severity)
MITRE CAPEC-655 (Avoid Security Tool Identification by Adding Data) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary adds data to a file to increase the file size beyond what security tools are capable of handling
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-655-avoid-security-tool-identification-by-adding-data
CAPEC-656 - MITRE CAPEC-656: Voice Phishing (Detailed Attack Pattern - High Severity)
MITRE CAPEC-656 (Voice Phishing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets users with a phishing attack for the purpose of soliciting account passwords or sensitive information from the user. Voice P
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-656-voice-phishing
CAPEC-657 - MITRE CAPEC-657: Malicious Automated Software Update via Spoofing (High Severity)
MITRE CAPEC-657 (Malicious Automated Software Update via Spoofing) is an attack pattern in which an attacker uses identity or content spoofing to trick a client into performing an automated software update from a malicious source. Likelihood: High. Severity: High. Maps to MITRE A
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-657-malicious-automated-software-update
CAPEC-660 - MITRE CAPEC-660: Root/Jailbreak Detection Evasion via Hooking (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-660 (Root/Jailbreak Detection Evasion via Hooking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary forces a non-restricted mobile application to load arbitrary code or code files, via Hooking, with the
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-660-root-jailbreak-detection-evasion-via-hooking
CAPEC-661 - MITRE CAPEC-661: Root/Jailbreak Detection Evasion via Debugging (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-661 (Root/Jailbreak Detection Evasion via Debugging) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary inserts a debugger into the program entry point of a mobile application to modify the application bi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-661-root-jailbreak-detection-evasion-via-debugging
CAPEC-662 - MITRE CAPEC-662: Adversary in the Browser (AiTB) (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-662 (Adversary in the Browser (AiTB)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits security vulnerabilities or inherent functionalities of a web browser, in order to manipulate traffic betw
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-662-adversary-in-the-browser-aitb
CAPEC-663 - MITRE CAPEC-663: Exploitation of Transient Instruction Execution (Standard Attack Pattern - Very High Severity)
MITRE CAPEC-663 (Exploitation of Transient Instruction Execution) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a hardware design flaw in a CPU implementation of transient instruction execution to expos
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-663-exploitation-of-transient-instruction-execution
CAPEC-664 - MITRE CAPEC-664: Server Side Request Forgery (Standard Attack Pattern - High Severity)
MITRE CAPEC-664 (Server Side Request Forgery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits improper input validation by submitting maliciously crafted input to a target application running on a server,
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-664-server-side-request-forgery
CAPEC-665 - MITRE CAPEC-665: Exploitation of Thunderbolt Protection Flaws (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-665 (Exploitation of Thunderbolt Protection Flaws) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary leverages a firmware weakness within the Thunderbolt protocol, on a computing device to manipulate Thu
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-665-exploitation-of-thunderbolt-protection-flaws
CAPEC-666 - MITRE CAPEC-666: BlueSmacking (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-666 (BlueSmacking) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses Bluetooth flooding to transfer large packets to Bluetooth enabled devices over the L2CAP protocol with the goal of creating a DoS
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-666-bluesmacking
CAPEC-667 - MITRE CAPEC-667: Bluetooth Impersonation AttackS (BIAS) (Detailed Attack Pattern - High Severity)
MITRE CAPEC-667 (Bluetooth Impersonation AttackS (BIAS)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary disguises the MAC address of their Bluetooth enabled device to one for which there exists an active and trus
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-667-bluetooth-impersonation-attacks-bias
CAPEC-668 - MITRE CAPEC-668: Key Negotiation of Bluetooth Attack (KNOB) (Standard Attack Pattern - High Severity)
MITRE CAPEC-668 (Key Negotiation of Bluetooth Attack (KNOB)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary can exploit a flaw in Bluetooth key negotiation allowing them to decrypt information sent between two de
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-668-key-negotiation-of-bluetooth-attack-knob
CAPEC-669 - MITRE CAPEC-669: Alteration of a Software Update (Standard Attack Pattern - High Severity)
MITRE CAPEC-669 (Alteration of a Software Update) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to an organization's software update infrastructure inserts malware into the content of an outgoing upd
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-669-alteration-of-a-software-update
CAPEC-670 - MITRE CAPEC-670: Software Development Tools Maliciously Altered (Detailed Attack Pattern - High Severity)
MITRE CAPEC-670 (Software Development Tools Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with the ability to alter tools used in a development environment causes software to be developed wi
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-670-software-development-tools-maliciously-altered
CAPEC-671 - MITRE CAPEC-671: Requirements for ASIC Functionality Maliciously Altered (Detailed Attack Pattern - High Severity)
MITRE CAPEC-671 (Requirements for ASIC Functionality Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary with access to functional requirements for an application specific integrated circuit (ASIC
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-671-requirements-for-asic-functionality-maliciously-altered
CAPEC-672 - MITRE CAPEC-672: Malicious Code Implanted During Chip Programming (Detailed Attack Pattern - High Severity)
MITRE CAPEC-672 (Malicious Code Implanted During Chip Programming) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. During the programming step of chip manufacture, an adversary with access and necessary technical skills malici
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-672-malicious-code-implanted-during-chip-programming
CAPEC-673 - MITRE CAPEC-673: Developer Signing Maliciously Altered Software (Detailed Attack Pattern - High Severity)
MITRE CAPEC-673 (Developer Signing Maliciously Altered Software) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Software produced by a reputable developer is clandestinely infected with malicious code and then digitally signe
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-673-developer-signing-maliciously-altered-software
CAPEC-674 - MITRE CAPEC-674: Design for FPGA Maliciously Altered (Detailed Attack Pattern - High Severity)
MITRE CAPEC-674 (Design for FPGA Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary alters the functionality of a field-programmable gate array (FPGA) by causing an FPGA configuration memory chip
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-674-design-for-fpga-maliciously-altered
CAPEC-675 - MITRE CAPEC-675: Retrieve Data from Decommissioned Devices (Standard Attack Pattern - Medium Severity)
MITRE CAPEC-675 (Retrieve Data from Decommissioned Devices) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains decommissioned, recycled, or discarded systems and devices that can include an organization's int
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-675-retrieve-data-from-decommissioned-devices
CAPEC-676 - MITRE CAPEC-676: NoSQL Injection (Standard Attack Pattern - High Severity)
MITRE CAPEC-676 (NoSQL Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets software that constructs NoSQL statements based on user input or with parameters vulnerable to operator replacement in orde
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-676-nosql-injection
CAPEC-677 - MITRE CAPEC-677: Server Motherboard Compromise (Detailed Attack Pattern - High Severity)
MITRE CAPEC-677 (Server Motherboard Compromise) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Malware is inserted in a server motherboard (e.g., in the flash memory) in order to alter server functionality from that intended.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-677-server-motherboard-compromise
CAPEC-678 - MITRE CAPEC-678: System Build Data Maliciously Altered (Detailed Attack Pattern - High Severity)
MITRE CAPEC-678 (System Build Data Maliciously Altered) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. During the system build process, the system is deliberately misconfigured by the alteration of the build data. Access to s
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-678-system-build-data-maliciously-altered
CAPEC-679 - MITRE CAPEC-679: Exploitation of Improperly Configured or Implemented Memory Protections (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-679 (Exploitation of Improperly Configured or Implemented Memory Protections) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of missing or incorrectly configured access control within
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-679-exploitation-of-improperly-configured-or-implemented-memory
CAPEC-680 - MITRE CAPEC-680: Exploitation of Improperly Controlled Registers (Detailed Attack Pattern - High Severity)
MITRE CAPEC-680 (Exploitation of Improperly Controlled Registers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits missing or incorrectly configured access control within registers to read/write data that
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-680-exploitation-of-improperly-controlled-registers
CAPEC-681 - MITRE CAPEC-681: Exploitation of Improperly Controlled Hardware Security Identifiers (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-681 (Exploitation of Improperly Controlled Hardware Security Identifiers) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of missing or incorrectly configured security identifiers (e.g.
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-681-exploitation-of-improperly-controlled-hardware-security-iden
CAPEC-682 - MITRE CAPEC-682: Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities (Standard Attack Pattern - High Severity)
MITRE CAPEC-682 (Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may exploit vulnerable code (i.e., firmware or ROM) that is unpatchable. Unpa
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-682-exploitation-of-firmware-or-rom-code-with-unpatchable
CAPEC-690 - MITRE CAPEC-690: Metadata Spoofing (Meta Attack Pattern - High Severity)
MITRE CAPEC-690 (Metadata Spoofing) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary alters the metadata of a resource (e.g., file, directory, repository, etc.) to present a malicious resource as legitimate/credible. L
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-690-metadata-spoofing
CAPEC-691 - MITRE CAPEC-691: Spoof Open-Source Software Metadata (Standard Attack Pattern - High Severity)
MITRE CAPEC-691 (Spoof Open-Source Software Metadata) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs open-source software metadata in an attempt to masquerade malicious software as popular, maintained, and
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-691-spoof-open-source-software-metadata
CAPEC-692 - MITRE CAPEC-692: Spoof Version Control System Commit Metadata (Detailed Attack Pattern - High Severity)
MITRE CAPEC-692 (Spoof Version Control System Commit Metadata) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs metadata pertaining to a Version Control System (VCS) (e.g., Git) repository's commits to decei
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-692-spoof-version-control-system-commit-metadata
CAPEC-693 - MITRE CAPEC-693: StarJacking (Detailed Attack Pattern - High Severity)
MITRE CAPEC-693 (StarJacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary spoofs software popularity metadata to deceive users into believing that a maliciously provided package is widely used and originates f
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-693-starjacking
CAPEC-694 - MITRE CAPEC-694: System Location Discovery (Standard Attack Pattern - Very Low Severity)
MITRE CAPEC-694 (System Location Discovery) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary collects information about the target system in an attempt to identify the system's geographical location. Information ga
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-694-system-location-discovery
CAPEC-695 - MITRE CAPEC-695: Repo Jacking (Detailed Attack Pattern - High Severity)
MITRE CAPEC-695 (Repo Jacking) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary takes advantage of the redirect property of directly linked Version Control System (VCS) repositories to trick users into incorporatin
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-695-repo-jacking
CAPEC-696 - MITRE CAPEC-696: Load Value Injection (Detailed Attack Pattern - Very High Severity)
MITRE CAPEC-696 (Load Value Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a hardware design flaw in a CPU implementation of transient instruction execution in which a faulting or assisted loa
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-696-load-value-injection
CAPEC-697 - MITRE CAPEC-697: DHCP Spoofing (Standard Attack Pattern - High Severity)
MITRE CAPEC-697 (DHCP Spoofing) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary masquerades as a legitimate Dynamic Host Configuration Protocol (DHCP) server by spoofing DHCP traffic, with the goal of redirecting
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-697-dhcp-spoofing
CAPEC-698 - MITRE CAPEC-698: Install Malicious Extension (Detailed Attack Pattern - High Severity)
MITRE CAPEC-698 (Install Malicious Extension) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary directly installs or tricks a user into installing a malicious extension into existing trusted software, with the goal
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-698-install-malicious-extension
CAPEC-699 - MITRE CAPEC-699: Eavesdropping on a Monitor (Meta Attack Pattern - High Severity)
MITRE CAPEC-699 (Eavesdropping on a Monitor) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An Adversary can eavesdrop on the content of an external monitor through the air without modifying any cable or installing software, just
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-699-eavesdropping-on-a-monitor
CAPEC-700 - MITRE CAPEC-700: Network Boundary Bridging (Standard Attack Pattern - High Severity)
MITRE CAPEC-700 (Network Boundary Bridging) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary which has gained elevated access to network boundary devices may use these devices to create a channel to bridge trusted
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-700-network-boundary-bridging
CAPEC-701 - MITRE CAPEC-701: Browser in the Middle (BiTM) (Standard Attack Pattern - High Severity)
MITRE CAPEC-701 (Browser in the Middle (BiTM)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits the inherent functionalities of a web browser, in order to establish an unnoticed remote desktop connection i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-701-browser-in-the-middle-bitm
CAPEC-702 - MITRE CAPEC-702: Exploiting Incorrect Chaining or Granularity of Hardware Debug Components (Detailed Attack Pattern - Medium Severity)
MITRE CAPEC-702 (Exploiting Incorrect Chaining or Granularity of Hardware Debug Components) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits incorrect chaining or granularity of hardware debug components i
Bidda node: https://bidda.com/intelligence/mitre-capec-capec-702-exploiting-incorrect-chaining-or-granularity-of-hardware-deb
Full list: https://bidda.com/mitre-capec
MITRE source: https://capec.mitre.org