| Home > CAPEC List > CAPEC-637: Collect Data from Clipboard (Version 3.9) |
|
Low
Low
| Nature | Type | ID | Name |
|---|---|---|---|
| ChildOf | Standard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern. | 150 | Collect Data from Common Resource Locations |
| View Name | Top Level Categories |
|---|---|
| Domains of Attack | Software |
| Mechanisms of Attack | Collect and Analyze Information |
Find an application that allows copying sensititve data to clipboad: An adversary first needs to find an application that allows copying and pasting of sensitive information. This could be an application that prints out temporary passwords to the screen, private email addresses, or any other sensitive information or data
Target users of the application: An adversary will target users of the application in order to obtain the information in their clipboard on a periodic basic
| Techniques |
|---|
| Install malware on a user's system designed to log clipboard contents periodically |
| Get the user to click on a malicious link that will bring them to an application to log the contents of the clipboard |
Follow-up attack: Use any sensitive information found to carry out a follow-up attack
| Scope | Impact | Likelihood |
|---|---|---|
Confidentiality | Read Data |
| CWE-ID | Weakness Name |
|---|---|
| 267 | Privilege Defined With Unsafe Actions |
| Entry ID | Entry Name |
|---|---|
| 1115 | Clipboard Data |
| Submissions | ||
|---|---|---|
| Submission Date | Submitter | Organization |
| 2018年07月31日 (Version 2.12) | CAPEC Content Team | |
| Modifications | ||
| Modification Date | Modifier | Organization |
| 2019年09月30日 (Version 3.2) | CAPEC Content Team | The MITRE Corporation |
| Updated Related_Attack_Patterns | ||
| 2020年07月30日 (Version 3.3) | CAPEC Content Team | The MITRE Corporation |
| Updated Description, Mitigations, Related_Attack_Patterns | ||
| 2021年10月21日 (Version 3.6) | CAPEC Content Team | The MITRE Corporation |
| Updated Execution_Flow | ||
|
Use of the Common Attack Pattern Enumeration and Classification (CAPEC), and the associated references from this website are subject to the Terms of Use. Copyright © 2007–2025, The MITRE Corporation. CAPEC and the CAPEC logo are trademarks of The MITRE Corporation. |
||