Umbra Wiki attack-pattern attack-pattern/CAPEC-309
Back to wiki

CAPEC-309 — Network Topology Mapping

provenance: imported · ATT&CK: T1016 T1049 T1590 · CWE: CWE-200

CAPEC-309: Network Topology Mapping

MITRE CAPEC attack pattern

Status Draft
Typical severity Low
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary engages in scanning activities to map network nodes, hosts, devices, and routes. Adversaries usually perform this type of network reconnaissance during the early stages of attack against an external network. Many types of scanning utilities are typically employed, including ICMP tools, network mappers, port scanners, and route testing utilities such as traceroute.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-200

ATT&CK techniques: T1016, T1049, T1590

Prerequisites

  • None

Consequences

  • Confidentiality: Other

Source