CAPEC Definitions

    CAPEC Definitions / CAPEC-580

    CAPEC-580: System Footprinting

    An adversary engages in active probing and exploration activities to determine security information about a remote target system. Often times adversaries will rely on remote applications that can be probed for system configurations.

    Severity:Low
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    Keep patches up to date by installing weekly or daily if possible.

    Identify programs that may be used to acquire peripheral information and block them by using a software restriction policy or tools that restrict program execution by using a process allowlist.

    Relationships with other CAPECs

    CAPEC-169: Footprinting

    Prerequisites

    The adversary must have logical access to the target network and system.

    Related Weaknesses

    CWE-204: Observable Response Discrepancy

    CWE-205: Observable Behavioral Discrepancy

    CWE-208: Observable Timing Discrepancy