CAPEC

CAPEC catalogues attack patterns, describing how weaknesses get exploited in practice.

Where CWE names the kind of flaw, CAPEC names the way somebody uses it. It is most useful during design and threat modelling, as a structured prompt for how a given weakness would actually be attacked, rather than as something to work through operationally.

Checked against the primary source.

More on Frameworks & standards