Esc
Asset Vulnerability Enumeration
Definition
Asset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 2 techniques in this category, Asset Vulnerability Enumeration.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Asset Vulnerability Enumeration | D3-AVE | Asset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities. | |
| - Container Image Analysis | D3-CIA | Analyzing a Container Image with respect to a set of policies. | Container Image Scanning |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , and .
Privilege Escalation
Boot or Logon Autostart Execution
Event Triggered Execution
Execution
Software Deployment Tools
Hijack Execution Flow
Trusted Developer Utilities Proxy Execution
Lateral Movement
Software Deployment Tools
Stealth
System Binary Proxy Execution
Pre-OS Boot
Hijack Execution Flow
Rootkit
Trusted Developer Utilities Proxy Execution
Hide Artifacts
Virtualization/Sandbox Evasion
Persistence
Server Software Component
Office Application Startup
Implant Internal Image
Boot or Logon Autostart Execution
Compromise Host Software Binary
Pre-OS Boot
Event Triggered Execution
Software Extensions
Initial Access
Supply Chain Compromise
Impact
Inhibit System Recovery
Service Stop
Credential Access
Input Capture
Exploitation for Credential Access
Steal or Forge Authentication Certificates
References
All
Patent
The following references were used to develop the Asset Vulnerability Enumeration knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Automated computer vulnerability resolution system
Reference Type: Patent Organization: McAfee LLC Author: Carl E. Banzhof
Security vulnerability information aggregation
Reference Type: Patent Organization: Nokia Technologies Oy Author: Christophe Gustave, Stanley Taihai Chow, Douglas Wiemer
System and method for vulnerability risk analysis
Reference Type: Patent Organization: CA Inc Author: Matthew Cruz Elder, Darrell Martin Kienzle, Pratyusa K. Manadhata, Ryan Kumar Persaud