Common Attack Pattern Enumeration and Classification (CAPEC)

A Structured Catalog of Adversary Attack Patterns

What is Common Attack Pattern Enumeration and Classification (CAPEC)?

The CAPEC attack pattern catalog is a publicly available classification of common approaches adversaries use to exploit weaknesses in applications and other cyber-enabled capabilities. Each pattern describes recurring attack attributes and methods, the challenges an adversary addresses, and ways defenders can reduce the attack’s effectiveness.

CAPEC relates attacker behavior to the weaknesses that enable it. It does not identify a particular Vulnerability or prove that a named threat actor used a method. CAPEC also differs from MITRE ATT&CK: CAPEC abstracts how attacks exploit weaknesses, while ATT&CK organizes knowledge of observed adversary tactics and techniques.

What is CAPEC used for?

Security architects, developers, testers, threat analysts, and incident responders use CAPEC to structure Threat Analysis and connect plausible attack patterns to requirements, design reviews, threat models, abuse cases, and security testing. Mappings between attack patterns and weakness classes can help teams reason from adversary methods toward preventive controls and mitigations.

CAPEC provides reusable abstractions rather than a complete threat model for a specific environment. Teams must select patterns according to architecture, assets, exposure, and credible adversaries. Leaders can use that analysis to challenge design assumptions and focus assurance work, but should combine CAPEC with system context, current threat intelligence, and validation evidence.

Continue reading

Mean Time to Failure (MTTF)
Non-Repairable System Reliability Metric
Spoofing
Identity Impersonation in Cyber Attacks
Digital Forensics and Incident Response (DFIR)
Investigating and Responding to Incidents

Please note!
Any use of this website requires prior agreement to our Terms of Use, Privacy Policy, and Cookie Policy.
If you do not fully agree to all of them, do not use this website.