Mapping NoteWeekly
Mapping note: the standard chain loses cross-site request forgery
Updated 12 August 2026 · Timeframe: Current CAPEC-to-ATT&CK coverage; weakness rotates weekly
The common way to connect a weakness to attacker behaviour chains it through attack patterns (CAPEC) to techniques (ATT&CK). This week's weakness, CWE-352 (cross-site request forgery): 4 attack pattern(s) reference it and the chain reaches 0 ATT&CK technique(s). Only 177 of 559 attack patterns carry any technique at all, so common weaknesses dead-end. We map weakness to technique directly, so the link survives.
Why it matters
A tool built on that chain reports no attacker techniques for cross-site request forgery, which is a mapping failure, not a fact about the weakness. Absence in a chained mapping usually means the chain broke, not that the weakness is harmless.
What to do
- Security leaders. When a tool shows a weakness mapping to no attacker techniques, ask whether it derived that through a chain before treating it as low risk.
- Lean IT orgs. Prefer direct weakness-to-technique views; the intermediate attack-pattern step silently drops the weaknesses you see most.
- MSPs. Offer clients a direct weakness-to-ATT&CK view; the public chained mappings under-report exactly the common weaknesses.
Our take
Mapping frameworks directly, instead of chaining through a lossy intermediate, is a concrete accuracy advantage we can show rather than assert.
Earlier issues
Past states of this signal, most recent first.
09 August 2026 Mapping note: the standard chain loses path traversal
Timeframe: Current CAPEC-to-ATT&CK coverage; weakness rotates weekly
The common way to connect a weakness to attacker behaviour chains it through attack patterns (CAPEC) to techniques (ATT&CK). This week's weakness, CWE-22 (path traversal): 5 attack pattern(s) reference it and the chain reaches 0 ATT&CK technique(s). Only 177 of 559 attack patterns carry any technique at all, so common weaknesses dead-end. We map weakness to technique directly, so the link survives.
02 August 2026 Mapping note: the standard chain loses SQL injection
Timeframe: Current CAPEC-to-ATT&CK coverage; weakness rotates weekly
The common way to connect a weakness to attacker behaviour chains it through attack patterns (CAPEC) to techniques (ATT&CK). This week's weakness, CWE-89 (SQL injection): 6 attack pattern(s) reference it and the chain reaches 0 ATT&CK technique(s). Only 177 of 559 attack patterns carry any technique at all, so common weaknesses dead-end. We map weakness to technique directly, so the link survives.
26 July 2026 Mapping note: the standard chain loses cross-site scripting (XSS)
Timeframe: Current CAPEC-to-ATT&CK coverage; weakness rotates weekly
The common way to connect a weakness to attacker behaviour chains it through attack patterns (CAPEC) to techniques (ATT&CK). This week's weakness, CWE-79 (cross-site scripting (XSS)): 6 attack pattern(s) reference it and the chain reaches 0 ATT&CK technique(s). Only 177 of 559 attack patterns carry any technique at all, so common weaknesses dead-end. We map weakness to technique directly, so the link survives.