CAPEC — Common Attack Pattern Enumeration
CAPEC (Common Attack Pattern Enumeration and Classification) is a comprehensive dictionary and classification taxonomy of known attacks used by adversaries. By cataloging threat mechanisms, severity levels, execution domains, and underlying structural vulnerability links, CAPEC allows cybersecurity teams to trace back attack behaviors to specific software and hardware weaknesses (CWE).
Notable Attack Patterns
Accessing Functionality Not Properly Constrained by ACLs
Buffer Overflow via Environment Variables
Overflow Buffers
Server Side Include (SSI) Injection
Filter CAPEC Data
Attack Patterns per Domain
CAPEC Hierarchy Overview
Patterns with/without CWE Mapping
Top CAPEC by Related CWE Count
Understanding CAPEC Fields
identifier
The unique standardized designator for each specific adversarial attack pattern cataloged (e.g., CAPEC-100).
name & description
A descriptive header and a detailed explanation of the threat mechanics, attack workflow, obstacles, and severity results.
execution domains
The technological environments targeted by the pattern: Software, Hardware, Network, Social Engineering, or Physical Systems.
hierarchy relations
Specifies the taxonomic relationships between items. Can point to parent categories (ChildOf) or dictate action orders (CanPrecede).
CWE links
Direct linkages back to the system software/hardware design weaknesses and flaws exploited by this attack pattern.