Attack patterns (CAPEC)
558 pages, showing 401–500, ordered by identifier.
- CAPEC-577 — Owner Footprinting An adversary exploits functionality meant to identify information about the primary users on the target system to an...
- CAPEC-578 — Disable Security Software An adversary exploits a weakness in access control to disable security tools so that detection does not occur. This...
- CAPEC-579 — Replace Winlogon Helper DLL Winlogon is a part of Windows that performs logon actions. In Windows systems prior to Windows Vista, a registry key...
- CAPEC-58 — Restful Privilege Elevation An adversary identifies a Rest HTTP (Get, Put, Delete) style permission method allowing them to perform various...
- CAPEC-580 — System Footprinting An adversary engages in active probing and exploration activities to determine security information about a remote...
- CAPEC-581 — Security Software Footprinting Adversaries may attempt to get a listing of security tools that are installed on the system and their...
- CAPEC-582 — Route Disabling An adversary disables the network route between two targets. The goal is to completely sever the communications...
- CAPEC-583 — Disabling Network Hardware In this attack pattern, an adversary physically disables networking hardware by powering it down or disconnecting...
- CAPEC-584 — BGP Route Disabling An adversary suppresses the Border Gateway Protocol (BGP) advertisement for a route so as to render the underlying...
- CAPEC-585 — DNS Domain Seizure In this attack pattern, an adversary influences a target's web-hosting company to disable a target domain. The goal...
- CAPEC-586 — Object Injection An adversary attempts to exploit an application by injecting additional, malicious content during its processing of...
- CAPEC-587 — Cross Frame Scripting (XFS) This attack pattern combines malicious Javascript and a legitimate webpage loaded into a concealed iframe. The...
- CAPEC-588 — DOM-Based XSS This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is inserted into the...
- CAPEC-589 — DNS Blocking An adversary intercepts traffic and intentionally drops DNS requests based on content in the request. In this way,...
- CAPEC-59 — Session Credential Falsification through Prediction This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used...
- CAPEC-590 — IP Address Blocking An adversary performing this type of attack drops packets destined for a target IP address. The aim is to prevent...
- CAPEC-591 — Reflected XSS This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is 'reflected' off a vulnerable...
- CAPEC-592 — Stored XSS An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently 'stored' within...
- CAPEC-593 — Session Hijacking This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing...
- CAPEC-594 — Traffic Injection An adversary injects traffic into the target's network connection. The adversary is therefore able to degrade or...
- CAPEC-595 — Connection Reset In this attack pattern, an adversary injects a connection reset packet to one or both ends of a target's connection....
- CAPEC-596 — TCP RST Injection An adversary injects one or more TCP RST packets to a target after the target has made a HTTP GET request. The goal...
- CAPEC-597 — Absolute Path Traversal An adversary with access to file system resources, either directly or via application logic, will use various file...
- CAPEC-598 — DNS Spoofing An adversary sends a malicious ('NXDOMAIN' ('No such domain') code, or DNS A record) response to a target's route...
- CAPEC-599 — Terrestrial Jamming In this attack pattern, the adversary transmits disruptive signals in the direction of the target's consumer-level...
- CAPEC-6 — Argument Injection An attacker changes the behavior or state of a targeted application through injecting data or command syntax through...
- CAPEC-60 — Reusing Session IDs (aka Session Replay) This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The...
- CAPEC-600 — Credential Stuffing An adversary tries known username/password combinations against different systems, applications, or services to gain...
- CAPEC-601 — Jamming An adversary uses radio noise or signals in an attempt to disrupt communications. By intentionally overwhelming...
- CAPEC-603 — Blockage An adversary blocks the delivery of an important system resource causing the system to fail or stop working.
- CAPEC-604 — Wi-Fi Jamming In this attack scenario, the attacker actively transmits on the Wi-Fi channel to prevent users from transmitting or...
- CAPEC-605 — Cellular Jamming In this attack scenario, the attacker actively transmits signals to overpower and disrupt the communication between...
- CAPEC-606 — Weakening of Cellular Encryption An attacker, with control of a Cellular Rogue Base Station or through cooperation with a Malicious Mobile Network...
- CAPEC-607 — Obstruction An attacker obstructs the interactions between system components. By interrupting or disabling these interactions,...
- CAPEC-608 — Cryptanalysis of Cellular Encryption The use of cryptanalytic techniques to derive cryptographic keys or otherwise effectively defeat cellular encryption...
- CAPEC-609 — Cellular Traffic Intercept Cellular traffic for voice and data from mobile devices and retransmission devices can be intercepted via numerous...
- CAPEC-61 — Session Fixation The attacker induces a client to establish a session with the target software using a session identifier provided by...
- CAPEC-610 — Cellular Data Injection Adversaries inject data into mobile technology traffic (data flows or signaling data) to disrupt communications or...
- CAPEC-611 — BitSquatting An adversary registers a domain name one bit different than a trusted domain. A BitSquatting attack leverages random...
- CAPEC-612 — WiFi MAC Address Tracking In this attack scenario, the attacker passively listens for WiFi messages and logs the associated Media Access...
- CAPEC-613 — WiFi SSID Tracking In this attack scenario, the attacker passively listens for WiFi management frame messages containing the Service...
- CAPEC-614 — Rooting SIM Cards SIM cards are the de facto trust anchor of mobile devices worldwide. The cards protect the mobile identity of...
- CAPEC-615 — Evil Twin Wi-Fi Attack Adversaries install Wi-Fi equipment that acts as a legitimate Wi-Fi network access point. When a device connects to...
- CAPEC-616 — Establish Rogue Location An adversary provides a malicious version of a resource at a location that is similar to the expected location of a...
- CAPEC-617 — Cellular Rogue Base Station In this attack scenario, the attacker imitates a cellular base station with their own 'rogue' base station...
- CAPEC-618 — Cellular Broadcast Message Request In this attack scenario, the attacker uses knowledge of the target’s mobile phone number (i.e., the number...
- CAPEC-619 — Signal Strength Tracking In this attack scenario, the attacker passively monitors the signal strength of the target’s cellular RF signal or...
- CAPEC-62 — Cross Site Request Forgery An attacker crafts malicious web links and distributes them (via web pages, email, etc.), typically in a targeted...
- CAPEC-620 — Drop Encryption Level An attacker forces the encryption level to be lowered, thus enabling a successful attack against the encrypted data.
- CAPEC-621 — Analysis of Packet Timing and Sizes An attacker may intercept and log encrypted transmissions for the purpose of analyzing metadata such as packet...
- CAPEC-622 — Electromagnetic Side-Channel Attack In this attack scenario, the attacker passively monitors electromagnetic emanations that are produced by the...
- CAPEC-623 — Compromising Emanations Attack Compromising Emanations (CE) are defined as unintentional signals which an attacker may intercept and analyze to...
- CAPEC-624 — Hardware Fault Injection The adversary uses disruptive signals or events, or alters the physical environment a device operates in, to cause...
- CAPEC-625 — Mobile Device Fault Injection Fault injection attacks against mobile devices use disruptive signals or events (e.g. electromagnetic pulses, laser...
- CAPEC-626 — Smudge Attack Attacks that reveal the password/passcode pattern on a touchscreen device by detecting oil smudges left behind by...
- CAPEC-627 — Counterfeit GPS Signals An adversary attempts to deceive a GPS receiver by broadcasting counterfeit GPS signals, structured to resemble a...
- CAPEC-628 — Carry-Off GPS Attack A common form of a GPS spoofing attack, commonly termed a carry-off attack begins with an adversary broadcasting...
- CAPEC-63 — Cross-Site Scripting (XSS) An adversary embeds malicious scripts in content that will be served to web browsers. The goal of the attack is for...
- CAPEC-630 — TypoSquatting An adversary registers a domain name with at least one character different than a trusted domain. A TypoSquatting...
- CAPEC-631 — SoundSquatting An adversary registers a domain name that sounds the same as a trusted domain, but has a different spelling. A...
- CAPEC-632 — Homograph Attack via Homoglyphs An adversary registers a domain name containing a homoglyph, leading the registered domain to appear the same as a...
- CAPEC-633 — Token Impersonation An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a...
- CAPEC-634 — Probe Audio and Video Peripherals The adversary exploits the target system's audio and video functionalities through malware or scheduled tasks. The...
- CAPEC-635 — Alternative Execution Due to Deceptive Filenames The extension of a file name is often used in various contexts to determine the application that is used to open and...
- CAPEC-636 — Hiding Malicious Data or Code within Files Files on various operating systems can have a complex format which allows for the storage of other data, in addition...
- CAPEC-637 — Collect Data from Clipboard The adversary exploits an application that allows for the copying of sensitive data or information by collecting...
- CAPEC-638 — Altered Component Firmware An adversary exploits systems features and/or improperly protected firmware of hardware components, such as Hard...
- CAPEC-639 — Probe System Files An adversary obtains unauthorized information due to improperly protected files. If an application stores sensitive...
- CAPEC-64 — Using Slashes and URL Encoding Combined to Bypass Validation Logic This attack targets the encoding of the URL combined with the encoding of the slash characters. An attacker can take...
- CAPEC-640 — Inclusion of Code in Existing Process The adversary takes advantage of a bug in an application failing to verify the integrity of the running process to...
- CAPEC-641 — DLL Side-Loading An adversary places a malicious version of a Dynamic-Link Library (DLL) in the Windows Side-by-Side (WinSxS)...
- CAPEC-642 — Replace Binaries Adversaries know that certain binaries will be regularly executed as part of normal processing. If these binaries...
- CAPEC-643 — Identify Shared Files/Directories on System An adversary discovers connections between systems by exploiting the target system's standard practice of revealing...
- CAPEC-644 — Use of Captured Hashes (Pass The Hash) An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems...
- CAPEC-645 — Use of Captured Tickets (Pass The Ticket) An adversary uses stolen Kerberos tickets to access systems/resources that leverage the Kerberos authentication...
- CAPEC-646 — Peripheral Footprinting Adversaries may attempt to obtain information about attached peripheral devices and components connected to a...
- CAPEC-647 — Collect Data from Registries An adversary exploits a weakness in authorization to gather system-specific data and sensitive information within a...
- CAPEC-648 — Collect Data from Screen Capture An adversary gathers sensitive information by exploiting the system's screen capture functionality. Through...
- CAPEC-649 — Adding a Space to a File Extension An adversary adds a space character to the end of a file extension and takes advantage of an application that does...
- CAPEC-65 — Sniff Application Code An adversary passively sniffs network communications and captures application code bound for an authorized client....
- CAPEC-650 — Upload a Web Shell to a Web Server By exploiting insufficient permissions, it is possible to upload a web shell to a web server in such a way that it...
- CAPEC-651 — Eavesdropping An adversary intercepts a form of communication (e.g. text, audio, video) by way of software (e.g., microphone and...
- CAPEC-652 — Use of Known Kerberos Credentials An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account...
- CAPEC-653 — Use of Known Operating System Credentials An adversary guesses or obtains (i.e. steals or purchases) legitimate operating system credentials (e.g....
- CAPEC-654 — Credential Prompt Impersonation An adversary, through a previously installed malicious application, impersonates a credential prompt in an attempt...
- CAPEC-655 — Avoid Security Tool Identification by Adding Data An adversary adds data to a file to increase the file size beyond what security tools are capable of handling in an...
- CAPEC-656 — Voice Phishing An adversary targets users with a phishing attack for the purpose of soliciting account passwords or sensitive...
- CAPEC-657 — Malicious Automated Software Update via Spoofing An attackers uses identify or content spoofing to trick a client into performing an automated software update from a...
- CAPEC-66 — SQL Injection This attack exploits target software that constructs SQL statements based on user input. An attacker crafts input...
- CAPEC-660 — Root/Jailbreak Detection Evasion via Hooking An adversary forces a non-restricted mobile application to load arbitrary code or code files, via Hooking, with the...
- CAPEC-661 — Root/Jailbreak Detection Evasion via Debugging An adversary inserts a debugger into the program entry point of a mobile application to modify the application...
- CAPEC-662 — Adversary in the Browser (AiTB) An adversary exploits security vulnerabilities or inherent functionalities of a web browser, in order to manipulate...
- CAPEC-663 — Exploitation of Transient Instruction Execution An adversary exploits a hardware design flaw in a CPU implementation of transient instruction execution to expose...
- CAPEC-664 — Server Side Request Forgery An adversary exploits improper input validation by submitting maliciously crafted input to a target application...
- CAPEC-665 — Exploitation of Thunderbolt Protection Flaws An adversary leverages a firmware weakness within the Thunderbolt protocol, on a computing device to manipulate...
- CAPEC-666 — BlueSmacking An adversary uses Bluetooth flooding to transfer large packets to Bluetooth enabled devices over the L2CAP protocol...
- CAPEC-667 — Bluetooth Impersonation AttackS (BIAS) An adversary disguises the MAC address of their Bluetooth enabled device to one for which there exists an active and...
- CAPEC-668 — Key Negotiation of Bluetooth Attack (KNOB) An adversary can exploit a flaw in Bluetooth key negotiation allowing them to decrypt information sent between two...
- CAPEC-669 — Alteration of a Software Update An adversary with access to an organization’s software update infrastructure inserts malware into the content of an...
- CAPEC-67 — String Format Overflow in syslog() This attack targets applications and software that uses the syslog() function insecurely. If an application does not...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.