CAPEC-569: Collect Data as Provided by Users

Standard Draft

CAPEC版本: 3.9

更新日期: 2023-01-24

攻击模式描述

An attacker leverages a tool, device, or program to obtain specific information as provided by a user of the target system. This information is often needed by the attacker to launch a follow-on attack. This attack is different than Social Engineering as the adversary is not tricking or deceiving the user. Instead the adversary is putting a mechanism in place that captures the information that a user legitimately enters into a system. Deploying a keylogger, performing a UAC prompt, or wrapping the Windows default credential provider are all examples of such interactions.

分类映射

分类名称 条目ID 条目名称
ATTACK 1056 Input Capture
关键信息

CAPEC ID: CAPEC-569

抽象级别: Standard

状态: Draft

相关攻击模式