Umbra Wiki attack-pattern attack-pattern/CAPEC-37
Back to wiki

CAPEC-37 — Retrieve Embedded Sensitive Data

provenance: imported · ATT&CK: T1005 T1552.004 · CWE: CWE-226 CWE-311 CWE-312 CWE-314 CWE-315 CWE-318 CWE-525 CWE-1239 CWE-1258 CWE-1266 CWE-1272 CWE-1278 CWE-1301 CWE-1330

CAPEC-37: Retrieve Embedded Sensitive Data

MITRE CAPEC attack pattern

Status Draft
Typical severity Very High
Likelihood of attack High
Catalogue CAPEC 3.9 (2023-01-24)

Description

An attacker examines a target system to find sensitive data that has been embedded within it. This information can reveal confidential contents, such as account numbers or individual keys/credentials that can be used as an intermediate step in a larger attack.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-226, CWE-311, CWE-312, CWE-314, CWE-315, CWE-318, CWE-525, CWE-1239, CWE-1258, CWE-1266, CWE-1272, CWE-1278, CWE-1301, CWE-1330

ATT&CK techniques: T1005, T1552.004

Prerequisites

  • In order to feasibly execute this type of attack, some valuable data must be present in client software.
  • Additionally, this information must be unprotected, or protected in a flawed fashion, or through a mechanism that fails to resist reverse engineering, statistical, or other attack.

Skills required

  • Medium: The attacker must possess knowledge of client code structure as well as ability to reverse-engineer or decompile it or probe it in other ways. This knowledge is specific to the technology and language used for the client distribution

Consequences

  • Confidentiality: Read Data
  • Integrity: Modify Data
  • Confidentiality, Access Control, Authorization: Gain Privileges

Source