Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-383 — Harvesting Information via API Event Monitoring
CAPEC-383

Harvesting Information via API Event Monitoring

TLP:CLEAR

Description

Typical severity: Low. An adversary hosts an event within an application framework and then monitors the data exchanged during the course of the event for the purpose of harvesting any important data leaked during the transactions. One example could be harvesting lists of usernames or userIDs for the purpose of sending spam messages to those users. One example of this type of attack involves the adversary creating an event within the sub-application. Assume the adversary hosts a "virtual sale" of rare items. As other users enter the event, the attacker records via AiTM (CAPEC-94) proxy the user_ids and usernames of everyone who attends. The adversary would then be able to spam those users within the application using an automated script.

Mitigation

Leverage encryption techniques during information transactions so as to protect them from attack patterns of this kind.

Details

Platforms
Social-engineering
Social-engineering
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.