Threat Intelligence

CAPEC

Common Attack Pattern Enumeration and Classification

Community Global MITRE Since 2007

A catalogue of attack patterns, the method by which a weakness is exploited, cross-referenced to the CWE weaknesses they target and the ATT&CK techniques they realise.

It sits between the two: use it when a threat model needs to explain how a specific weakness becomes a specific technique.

At a glance

Category
Threat Intelligence
Jurisdiction
Global
Governance
MITRE
Status
Actively maintained; cross-referenced with CWE and ATT&CK
First released
2007

Links

Related frameworks

Other entries under Threat Intelligence.

See CAPEC in context

Open the interactive Data Landscape for Regulation to compare CAPEC against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.