Threat Intelligence
CAPEC
Common Attack Pattern Enumeration and Classification
Community
Global
MITRE
Since 2007
A catalogue of attack patterns, the method by which a weakness is exploited, cross-referenced to the CWE weaknesses they target and the ATT&CK techniques they realise.
It sits between the two: use it when a threat model needs to explain how a specific weakness becomes a specific technique.
At a glance
- Category
- Threat Intelligence
- Jurisdiction
- Global
- Governance
- MITRE
- Status
- Actively maintained; cross-referenced with CWE and ATT&CK
- First released
- 2007
Links
Related frameworks
Other entries under Threat Intelligence.
- MITRE ATT&CK: Adversarial Tactics, Techniques and Common Knowledge
- MITRE D3FEND: Defensive Countermeasures Knowledge Graph
- CWE: Common Weakness Enumeration
- STIX: Structured Threat Information Expression
- TAXII: Trusted Automated Exchange of Intelligence Information
See CAPEC in context
Open the interactive Data Landscape for Regulation to compare CAPEC against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.