Common Attack Pattern Enumeration and Classification
A Community Resource for Identifying and Understanding Attacks
A number of documents exist to help clarify the historical significance, current use, and future directions of CAPEC.
This document, which is posted on the CAPEC Reports page, contains descriptions of the various elements in the official CAPEC Schema. It provides a basic understanding of the CAPEC data structure and can be used as a useful guide for developing new CAPEC entries or adding content to existing entries. Previous versions of the schema documentation are available on the Archive page.
Release notes citing the difference between the current official version of the CAPEC List and CAPEC Schema in comparison to the most previous version are posted on the CAPEC Reports page. Difference reports for previous releases are available on the Archive page.
Understanding adversary behavior is increasingly important in cybersecurity. Two approaches exist for organizing knowledge about adversary behavior – CAPEC and ATT&CK, each focused on a specific set of use-cases. This page explains the similarities, differences, and relationship between CAPEC and ATT&CK and the role of each in cybersecurity.
Outreach and Enhancement
CAPEC Introductory Brochure
A brief two-page introduction to the CAPEC effort. February 2013.
PDF (111 KB)
An Introduction to Attack Patterns as a Software Assurance Knowledge Resource
OMG SwA Workshop 2007
PDF (2 MB)
Attack Patterns - Knowing Your Enemies in Order to Defeat Them
Paper - PDF (119 KB)
Slides - PDF (522 KB)
More information is available — Please select a different filter.