CAPEC 攻击模式
CAPEC 基础字段和已提取关联查询。
| CAPEC ID | 名称 | 抽象级别 | 状态 | ATT&CK 映射数 | 操作 |
|---|---|---|---|---|---|
| CAPEC-243 | XSS Targeting HTML Attributes | Detailed | Draft | 0 | |
| CAPEC-244 | XSS Targeting URI Placeholders | Detailed | Draft | 0 | |
| CAPEC-245 | XSS Using Doubled Characters | Detailed | Draft | 0 | |
| CAPEC-247 | XSS Using Invalid Characters | Detailed | Draft | 0 | |
| CAPEC-248 | Command Injection | Meta | Stable | 0 | |
| CAPEC-25 | Forced Deadlock | Meta | Stable | 1 | |
| CAPEC-250 | XML Injection | Standard | Draft | 0 | |
| CAPEC-251 | Local Code Inclusion | Standard | Stable | 1 | |
| CAPEC-252 | PHP Local File Inclusion | Detailed | Draft | 0 | |
| CAPEC-253 | Remote Code Inclusion | Standard | Draft | 0 | |
| CAPEC-256 | SOAP Array Overflow | Detailed | Draft | 0 | |
| CAPEC-26 | Leveraging Race Conditions | Meta | Stable | 0 | |
| CAPEC-261 | Fuzzing for garnering other adjacent user/sensitive data | Detailed | Draft | 0 | |
| CAPEC-263 | Force Use of Corrupted Files | Detailed | Draft | 0 | |
| CAPEC-267 | Leverage Alternate Encoding | Standard | Draft | 1 | |
| CAPEC-268 | Audit Log Manipulation | Standard | Draft | 4 | |
| CAPEC-27 | Leveraging Race Conditions via Symbolic Links | Detailed | Draft | 0 | |
| CAPEC-270 | Modification of Registry Run Keys | Detailed | Stable | 2 | |
| CAPEC-271 | Schema Poisoning | Standard | Draft | 0 | |
| CAPEC-272 | Protocol Manipulation | Meta | Draft | 0 |