Attack patterns (CAPEC)
558 pages, showing 301–400, ordered by identifier.
- CAPEC-472 — Browser Fingerprinting An attacker carefully crafts small snippets of Java Script to efficiently detect the type of browser the potential...
- CAPEC-473 — Signature Spoof An attacker generates a message or datablock that causes the recipient to believe that the message or datablock was...
- CAPEC-474 — Signature Spoofing by Key Theft An attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to...
- CAPEC-475 — Signature Spoofing by Improper Validation An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a...
- CAPEC-476 — Signature Spoofing by Misrepresentation An attacker exploits a weakness in the parsing or display code of the recipient software to generate a data blob...
- CAPEC-477 — Signature Spoofing by Mixing Signed and Unsigned Content An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content,...
- CAPEC-478 — Modification of Windows Service Configuration An adversary exploits a weakness in access control to modify the execution parameters of a Windows service. The goal...
- CAPEC-479 — Malicious Root Certificate An adversary exploits a weakness in authorization and installs a new root certificate on a compromised system....
- CAPEC-48 — Passing Local Filenames to Functions That Expect a URL This attack relies on client side code to access local files and resources instead of URLs. When the client browser...
- CAPEC-480 — Escaping Virtualization An adversary gains access to an application, service, or device with the privileges of an authorized or privileged...
- CAPEC-481 — Contradictory Destinations in Traffic Routing Schemes Adversaries can provide contradictory destinations when sending messages. Traffic is routed in networks using the...
- CAPEC-482 — TCP Flood An adversary may execute a flooding attack using the TCP protocol with the intent to deny legitimate users access to...
- CAPEC-485 — Signature Spoofing by Key Recreation An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic...
- CAPEC-486 — UDP Flood An adversary may execute a flooding attack using the UDP protocol with the intent to deny legitimate users access to...
- CAPEC-487 — ICMP Flood An adversary may execute a flooding attack using the ICMP protocol with the intent to deny legitimate users access...
- CAPEC-488 — HTTP Flood An adversary may execute a flooding attack using the HTTP protocol with the intent to deny legitimate users access...
- CAPEC-489 — SSL Flood An adversary may execute a flooding attack using the SSL protocol with the intent to deny legitimate users access to...
- CAPEC-49 — Password Brute Forcing An adversary tries every possible value for a password until they succeed. A brute force attack, if feasible...
- CAPEC-490 — Amplification An adversary may execute an amplification where the size of a response is far greater than that of the request that...
- CAPEC-491 — Quadratic Data Expansion An adversary exploits macro-like substitution to cause a denial of service situation due to excessive memory being...
- CAPEC-492 — Regular Expression Exponential Blowup An adversary may execute an attack on a program that uses a poor Regular Expression(Regex) implementation by...
- CAPEC-493 — SOAP Array Blowup An adversary may execute an attack on a web service that uses SOAP messages in communication. By sending a very...
- CAPEC-494 — TCP Fragmentation An adversary may execute a TCP Fragmentation attack against a target with the intention of avoiding filtering rules...
- CAPEC-495 — UDP Fragmentation An attacker may execute a UDP Fragmentation attack against a target server in an attempt to consume resources such...
- CAPEC-496 — ICMP Fragmentation An attacker may execute a ICMP Fragmentation attack against a target with the intention of consuming resources or...
- CAPEC-497 — File Discovery An adversary engages in probing and exploration activities to determine if common key files exists. Such files often...
- CAPEC-498 — Probe iOS Screenshots An adversary examines screenshot images created by iOS in an attempt to obtain sensitive information. This attack...
- CAPEC-499 — Android Intent Intercept An adversary, through a previously installed malicious application, intercepts messages from a trusted Android-based...
- CAPEC-50 — Password Recovery Exploitation An attacker may take advantage of the application feature to help users recover their forgotten passwords in order...
- CAPEC-500 — WebView Injection An adversary, through a previously installed malicious application, injects code into the context of a web page...
- CAPEC-501 — Android Activity Hijack An adversary intercepts an implicit intent sent to launch a Android-based trusted activity and instead launches a...
- CAPEC-502 — Intent Spoof An adversary, through a previously installed malicious application, issues an intent directed toward a specific...
- CAPEC-503 — WebView Exposure An adversary, through a malicious web page, accesses application specific functionality by leveraging interfaces...
- CAPEC-504 — Task Impersonation An adversary, through a previously installed malicious application, impersonates an expected or routine task in an...
- CAPEC-505 — Scheme Squatting An adversary, through a previously installed malicious application, registers for a URL scheme intended for a target...
- CAPEC-506 — Tapjacking An adversary, through a previously installed malicious application, displays an interface that misleads the user and...
- CAPEC-507 — Physical Theft An adversary gains physical access to a system or device through theft of the item. Possession of a system or device...
- CAPEC-508 — Shoulder Surfing In a shoulder surfing attack, an adversary observes an unaware individual's keystrokes, screen content, or...
- CAPEC-509 — Kerberoasting Through the exploitation of how service accounts leverage Kerberos authentication with Service Principal Names...
- CAPEC-51 — Poison Web Service Registry SOA and Web Services often use a registry to perform look up, get schema information, and metadata about services. A...
- CAPEC-510 — SaaS User Request Forgery An adversary, through a previously installed malicious application, performs malicious actions against a third-party...
- CAPEC-511 — Infiltration of Software Development Environment An attacker uses common delivery mechanisms such as email attachments or removable media to infiltrate the IDE...
- CAPEC-516 — Hardware Component Substitution During Baselining An adversary with access to system components during allocated baseline development can substitute a maliciously...
- CAPEC-517 — Documentation Alteration to Circumvent Dial-down An attacker with access to a manufacturer's documentation, which include descriptions of advanced technology and/or...
- CAPEC-518 — Documentation Alteration to Produce Under-performing Systems An attacker with access to a manufacturer's documentation alters the descriptions of system capabilities with the...
- CAPEC-519 — Documentation Alteration to Cause Errors in System Design An attacker with access to a manufacturer's documentation containing requirements allocation and software design...
- CAPEC-52 — Embedding NULL Bytes An adversary embeds one or more null bytes in input to the target software. This attack relies on the usage of a...
- CAPEC-520 — Counterfeit Hardware Component Inserted During Product Assembly An adversary with either direct access to the product assembly process or to the supply of subcomponents used in the...
- CAPEC-521 — Hardware Design Specifications Are Altered An attacker with access to a manufacturer's hardware manufacturing process documentation alters the design...
- CAPEC-522 — Malicious Hardware Component Replacement An adversary replaces legitimate hardware in the system with faulty counterfeit or tampered hardware in the supply...
- CAPEC-523 — Malicious Software Implanted An attacker implants malicious software into the system in the supply chain distribution channel, with purpose of...
- CAPEC-524 — Rogue Integration Procedures An attacker alters or establishes rogue processes in an integration facility in order to insert maliciously altered...
- CAPEC-528 — XML Flood An adversary may execute a flooding attack using XML messages with the intent to deny legitimate users access to a...
- CAPEC-529 — Malware-Directed Internal Reconnaissance Adversary uses malware or a similarly controlled application installed inside an organizational perimeter to gather...
- CAPEC-53 — Postfix, Null Terminate, and Backslash If a string is passed through a filter of some kind, then a terminal NULL may not be valid. Using alternate...
- CAPEC-530 — Provide Counterfeit Component An attacker provides a counterfeit component during the procurement process of a lower-tier component supplier to a...
- CAPEC-531 — Hardware Component Substitution An attacker substitutes out a tested and approved hardware component for a maliciously-altered hardware component....
- CAPEC-532 — Altered Installed BIOS An attacker with access to download and update system software sends a maliciously altered BIOS to the victim or...
- CAPEC-533 — Malicious Manual Software Update An attacker introduces malicious code to the victim's system by altering the payload of a software update, allowing...
- CAPEC-534 — Malicious Hardware Update An adversary introduces malicious hardware during an update or replacement procedure, allowing for additional...
- CAPEC-535 — Malicious Gray Market Hardware An attacker maliciously alters hardware components that will be sold on the gray market, allowing for victim...
- CAPEC-536 — Data Injected During Configuration An attacker with access to data files and processes on a victim's system injects malicious data into critical...
- CAPEC-537 — Infiltration of Hardware Development Environment An adversary, leveraging the ability to manipulate components of primary support systems and tools within the...
- CAPEC-538 — Open-Source Library Manipulation Adversaries implant malicious code in open source software (OSS) libraries to have it widely distributed, as OSS is...
- CAPEC-539 — ASIC With Malicious Functionality An attacker with access to the development environment process of an application-specific integrated circuit (ASIC)...
- CAPEC-54 — Query System for Information An adversary, aware of an application's location (and possibly authorized to use the application), probes an...
- CAPEC-540 — Overread Buffers An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined...
- CAPEC-541 — Application Fingerprinting An adversary engages in fingerprinting activities to determine the type or version of an application installed on a...
- CAPEC-542 — Targeted Malware An adversary develops targeted malware that takes advantage of a known vulnerability in an organizational...
- CAPEC-543 — Counterfeit Websites Adversary creates duplicates of legitimate websites. When users visit a counterfeit site, the site can gather...
- CAPEC-544 — Counterfeit Organizations An adversary creates a false front organizations with the appearance of a legitimate supplier in the critical life...
- CAPEC-545 — Pull Data from System Resources An adversary who is authorized or has the ability to search known system resources, does so with the intention of...
- CAPEC-546 — Incomplete Data Deletion in a Multi-Tenant Environment An adversary obtains unauthorized information due to insecure or incomplete data deletion in a multi-tenant...
- CAPEC-547 — Physical Destruction of Device or Component An adversary conducts a physical attack a device or component, destroying it such that it no longer functions as intended.
- CAPEC-548 — Contaminate Resource An adversary contaminates organizational information systems (including devices and networks) by causing them to...
- CAPEC-549 — Local Execution of Code An adversary installs and executes malicious code on the target system in an effort to achieve a negative technical...
- CAPEC-55 — Rainbow Table Password Cracking An attacker gets access to the database table where hashes of passwords are stored. They then use a rainbow table of...
- CAPEC-550 — Install New Service When an operating system starts, it also starts programs called services or daemons. Adversaries may install a new...
- CAPEC-551 — Modify Existing Service When an operating system starts, it also starts programs called services or daemons. Modifying existing services may...
- CAPEC-552 — Install Rootkit An adversary exploits a weakness in authentication to install malware that alters the functionality and information...
- CAPEC-554 — Functionality Bypass An adversary attacks a system by bypassing some or all functionality intended to protect it. Often, a system user...
- CAPEC-555 — Remote Services with Stolen Credentials This pattern of attack involves an adversary that uses stolen credentials to leverage remote services such as RDP,...
- CAPEC-556 — Replace File Extension Handlers When a file is opened, its file handler is checked to determine which program opens the file. File handlers are...
- CAPEC-558 — Replace Trusted Executable An adversary exploits weaknesses in privilege management or access control to replace a trusted executable with a...
- CAPEC-559 — Orbital Jamming In this attack pattern, the adversary sends disruptive signals at a target satellite using a rogue uplink station to...
- CAPEC-560 — Use of Known Domain Credentials An adversary guesses or obtains (i.e. steals or purchases) legitimate credentials (e.g. userID/password) to achieve...
- CAPEC-561 — Windows Admin Shares with Stolen Credentials An adversary guesses or obtains (i.e. steals or purchases) legitimate Windows administrator credentials (e.g....
- CAPEC-562 — Modify Shared File An adversary manipulates the files in a shared location by adding malicious programs, scripts, or exploit code to...
- CAPEC-563 — Add Malicious File to Shared Webroot An adversaries may add malicious content to a website through the open file share and then browse to that content...
- CAPEC-564 — Run Software at Logon Operating system allows logon scripts to be run whenever a specific user or users logon to a system. If adversaries...
- CAPEC-565 — Password Spraying In a Password Spraying attack, an adversary tries a small list (e.g. 3-5) of common or expected passwords, often...
- CAPEC-568 — Capture Credentials via Keylogger An adversary deploys a keylogger in an effort to obtain credentials directly from a system's user. After capturing...
- CAPEC-569 — Collect Data as Provided by Users An attacker leverages a tool, device, or program to obtain specific information as provided by a user of the target...
- CAPEC-57 — Utilizing REST's Trust in the System Resource to Obtain Sensitive Data This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and...
- CAPEC-571 — Block Logging to Central Repository An adversary prevents host-generated logs being delivered to a central location in an attempt to hide indicators of...
- CAPEC-572 — Artificially Inflate File Sizes An adversary modifies file contents by adding data to files for several reasons. Many different attacks could...
- CAPEC-573 — Process Footprinting An adversary exploits functionality meant to identify information about the currently running processes on the...
- CAPEC-574 — Services Footprinting An adversary exploits functionality meant to identify information about the services on the target system to an...
- CAPEC-575 — Account Footprinting An adversary exploits functionality meant to identify information about the domain accounts and their permissions on...
- CAPEC-576 — Group Permission Footprinting An adversary exploits functionality meant to identify information about user groups and their permissions on the...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.