CAPEC
CAPEC: MITRE catalog for the structured description of typical attack patterns. The term is relevant for the assessment and design of modern security architecturesSecurity ArchitectureThe structured design of security controls, trust boundaries, data flows, and operational responsibilities. and should be applied within the specific technical and organizational context.
How it works and where it fits
CAPEC structures knowledge about potential adversaries, their objectives, capabilities, infrastructure, and observed behavior. Individual indicators are short-lived and easy to change, while behavioral patterns and technical relationships often have greater analytical value. Reporting should distinguish observed facts, assessments, and assumptions.
Practical security relevance
Practical use depends on source quality, timeliness, and relevance to the organization’s own attack surface. Information is prioritized, correlated with internal data, and converted into searches, detections, or safeguards. Investigation feedback continuously improves the assessment. Confidentiality and permitted sharing are as important as technical exchange formats.
Related concepts
- MITRE ATT&CKMITRE ATT&CKStructures known tactics and techniques of real-world cyberattacks.: Structures known tactics and techniques of real-world cyberattacks.
- Tactics, Techniques and ProceduresTactics, Techniques and ProceduresDescription of the typical objectives, methods, and procedures of threat actors.: Description of the typical objectives, methods, and procedures of threat actors.
- Common Vulnerabilities and ExposuresCommon Vulnerabilities and ExposuresStandardized identification of publicly known IT vulnerabilities.: Standardized identification of publicly known IT vulnerabilities.
- Cyber Kill ChainCyber Kill ChainModel describing the successive phases of a cyberattack.: Model describing the successive phases of a cyberattack.