Home > Glossary > CompTIA Cybersecurity Analyst+ > Common Attack Pattern Enumeration and Classification (CAPEC)

📖 What is Common Attack Pattern Enumeration and Classification (CAPEC)?

Common Attack Pattern Enumeration and Classification (CAPEC) is a comprehensive dictionary of known patterns of attack used by adversaries to exploit software vulnerabilities. It provides a way to categorize attack vectors and helps security analysts understand how a vulnerability might be exploited.

🥋 Sensei Says:

"CAPEC focuses on the attacker's perspective (how they do it), whereas CWE focuses on the developer's mistake (what is wrong)."

📚 Certification: CompTIA Cybersecurity Analyst+ (CS0-003)

🔑 What are the Key Concepts of Common Attack Pattern Enumeration and Classification (CAPEC)?

  • Focuses on the attacker's perspective, detailing the specific methods and techniques adversaries use to exploit vulnerabilities to achieve their goals.
  • Complements CWE by describing the attack pattern used to exploit a weakness, whereas CWE describes the underlying software flaw itself.
  • Used extensively in threat modeling to anticipate potential attack vectors and implement proactive defenses based on known adversary behaviors.
  • Organizes attack patterns into a hierarchical structure, allowing analysts to categorize similar techniques and identify broader trends in adversary tactics.
  • Provides a standardized vocabulary for security professionals to communicate how an exploit works, facilitating better collaboration during incident response.

🎯 How does Common Attack Pattern Enumeration and Classification (CAPEC) appear on the CS0-003 Exam?

You may be asked to distinguish between a software weakness and an attack pattern; you must identify CAPEC as the framework used to describe the 'how' of the exploit.

A scenario might describe a security analyst performing threat modeling for a new application; expect questions about using CAPEC to identify potential attack vectors based on known patterns.

Expect questions where you must map an observed adversary behavior during an incident to a standardized classification to help communicate the specific attack method to stakeholders.

❓ Frequently Asked Questions

How does CAPEC differ from the MITRE ATT&CK framework?

MITRE ATT&CK focuses on the high-level tactics and techniques of specific threat actors during a campaign, while CAPEC provides a more granular, generic dictionary of individual attack patterns regardless of the actor.


How can a security analyst practically apply CAPEC in a SOC?

Analysts use CAPEC to develop detection rules and 'attack trees.' By understanding the specific pattern, they can identify which logs or telemetry are necessary to detect that technique in their environment.

Related Terms from CompTIA Cybersecurity Analyst+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Common Attack Pattern Enumeration and Classification (CAPEC)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium