Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-65 — Sniff Application Code
CAPEC-65

Sniff Application Code

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. An adversary passively sniffs network communications and captures application code bound for an authorized client. Once obtained, they can use it as-is, or through reverse-engineering glean sensitive information or exploit the trust relationship between the client and server. Such code may belong to a dynamic update to the client, a patch being applied to a client component or any such interaction where the client is authorized to communicate with the server.

Mitigation

Design: Encrypt all communication between the client and server. | Implementation: Use SSL, SSH, SCP. | Operation: Use "ifconfig/ipconfig" or other tools to detect the sniffer installed in the network.

Details

Platforms
Communications
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.