Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-529 — Malware-Directed Internal Reconnaissance
CAPEC-529

Malware-Directed Internal Reconnaissance

TLP:CLEAR

Description

Typical severity: Medium. Likelihood of attack: Medium. Adversary uses malware or a similarly controlled application installed inside an organizational perimeter to gather information about the composition, configuration, and security mechanisms of a targeted application, system or network.

Mitigation

Keep patches up to date by installing weekly or daily if possible. | Identify programs that may be used to acquire peripheral information and block them by using a software restriction policy or tools that restrict program execution by using a process allowlist.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.