CCC.Core.TH15: Automated Enumeration and Reconnaissance by Non-human Entities
Threat ID:CCC.Core.TH15
Title:Automated Enumeration and Reconnaissance by Non-human Entities
Description:
Automated processes may be used to gather details about service and child resource elements such as APIs, file systems, or directories. This information can reveal vulnerabilities, misconfigurations, and the network topology, which can be used to plan an attack against the system, the service, or its child resources.
Related Capabilities
ID | Title | Description |
---|---|---|
CCC.Core.F14 | API Access | The service exposes a port enabling external actors to interact programmatically with the service and its resources using HTTP protocol methods such as GET, POST, PUT, and DELETE. |
External Mappings
Reference ID | Entry ID | Strength | Remarks |
---|---|---|---|
MITRE-ATT&CK | T1580 | 0 | Cloud Infrastructure Discovery |