Common Attack Pattern Enumeration and Classification
A Community Resource for Identifying and Understanding Attacks
A number of documents exist to help clarify the historical significance, current use, and future directions of CAPEC.
This document, which is posted on the CAPEC Reports page, contains descriptions of the various elements in the official CAPEC Schema. It provides a basic understanding of the CAPEC data structure and can be used as a useful guide for developing new CAPEC entries or adding content to existing entries. Previous versions of the schema documentation are available on the Archive page.
Release notes citing the difference between the current official version of the CAPEC List and CAPEC Schema in comparison to the most previous version are posted on the CAPEC Reports page. Difference reports for previous releases are available on the Archive page.
Understanding adversary behavior is increasingly important in cybersecurity. Two approaches exist for organizing knowledge about adversary behavior – CAPEC and ATT&CK, each focused on a specific set of use-cases. This page explains the similarities, differences, and relationship between CAPEC and ATT&CK and the role of each in cybersecurity.
CAPEC User Summit 2022
Session 1 - Pen Testing and Execution Flows
Talking Exploits, Session 1 - Pen Testing and Execution Flows - Navaneeth Krishnan Subramanian, CAPEC/CWE Program
CAPEC User Summit 2022 – Speakers List and Final Agenda (PNG, 145 KB)
CAPEC Introductory Brochure
A brief two-page introduction to the CAPEC effort. February 2013.
PDF (111 KB)
An Introduction to Attack Patterns as a Software Assurance Knowledge Resource
OMG SwA Workshop 2007
PDF (2 MB)
Attack Patterns - Knowing Your Enemies in Order to Defeat Them
Paper - PDF (119 KB)
Slides - PDF (522 KB)
More information is available — Please select a different filter.