Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-678 — System Build Data Maliciously Altered
CAPEC-678

System Build Data Maliciously Altered

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. During the system build process, the system is deliberately misconfigured by the alteration of the build data. Access to system configuration data files and build processes is susceptible to deliberate misconfiguration of the system.

Mitigation

Implement configuration management security practices that protect the integrity of software and associated data. | Monitor and control access to the configuration management system. | Harden centralized repositories against attack. | Establish acceptance criteria for configuration management check-in to assure integrity. | Plan for and audit the security of configuration management administration processes.

Details

Platforms
Supply-chain
Software
Hardware
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.