Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE
Class SecurityThreatExploit

Used to take advantage of weaknesses the victim has to gain access or information that is either inherently valuable, or that can be used to gain further access.

Attributes
SecurityThreat _securityThreat _securityThreat
SecurityThreatActor _securityThreatActor _securityThreatActor
SecurityThreatIndicator _securityThreatIndicator _securityThreatIndicator
SecurityThreatTechnique _securityThreatTechnique _securityThreatTechnique
SecurityThreatTool _securityThreatTool _securityThreatTool
SecurityVulnerability _securityVulnerability _securityVulnerability
EntityIdentification entityIdentification entityIdentification
String exploitType exploitType

An enumerated list of threa exploit types, such as:

Software Flaw
Weak Security Control
Cross-scripting Exploit
User-interaction Dependent Tool

String name name

A human readable name given to the exploit

«baseType» URI reference reference

A reference to additional information about a threat exploit.

String unauthorizedResults unauthorizedResults

Description the unauthorized results obtained through the use of this exploit


Properties:

Alias
Classifier Behavior
Is Abstractfalse
Is Activefalse
Is Leaffalse
Keywords
NameSecurityThreatExploit
Name Expression
NamespaceSecurity Threat ABE
Owned Template Signature
OwnerSecurity Threat ABE
Owning Template Parameter
PackageSecurity Threat ABE
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit
Representation
Stereotype
Template Parameter
VisibilityPublic

Attribute Details

 _securityThreat
Public SecurityThreat _securityThreat
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityThreatResultsIn
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Name_securityThreat
Name Expression
NamespaceSecurityThreatExploit
Opposite_securityThreatExploit
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::_securityThreat
Stereotype
Template Parameter
TypeSecurityThreat
Upper1
Upper Value(1)
VisibilityPublic


 _securityThreatActor
Public SecurityThreatActor _securityThreatActor
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurtyThreatActorInitiates
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower1
Lower Value(1)
Multiplicity1
Name_securityThreatActor
Name Expression
NamespaceSecurityThreatExploit
Opposite_securityThreatExploit
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::_securityThreatActor
Stereotype
Template Parameter
TypeSecurityThreatActor
Upper1
Upper Value(1)
VisibilityPublic


 _securityThreatIndicator
Public SecurityThreatIndicator _securityThreatIndicator
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityThreatIndicatorFurtherDescribedBy
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Name_securityThreatIndicator
Name Expression
NamespaceSecurityThreatExploit
Opposite_securityThreatExploit
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::_securityThreatIndicator
Stereotype
Template Parameter
TypeSecurityThreatIndicator
Upper1
Upper Value(1)
VisibilityPublic


 _securityThreatTechnique
Public SecurityThreatTechnique _securityThreatTechnique
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityThreatTechniqueUsedBy
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Name_securityThreatTechnique
Name Expression
NamespaceSecurityThreatExploit
Opposite_securityThreatExploit
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::_securityThreatTechnique
Stereotype
Template Parameter
TypeSecurityThreatTechnique
Upper1
Upper Value(1)
VisibilityPublic


 _securityThreatTool
Public SecurityThreatTool _securityThreatTool
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityThreatToolUsedBy
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Name_securityThreatTool
Name Expression
NamespaceSecurityThreatExploit
Opposite_securityThreatExploit
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::_securityThreatTool
Stereotype
Template Parameter
TypeSecurityThreatTool
Upper1
Upper Value(1)
VisibilityPublic


 _securityVulnerability
Public SecurityVulnerability _securityVulnerability
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityThreatExploitTargets
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Name_securityVulnerability
Name Expression
NamespaceSecurityThreatExploit
Opposite_securityThreatExploit
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::_securityVulnerability
Stereotype
Template Parameter
TypeSecurityVulnerability
Upper*
Upper Value(*)
VisibilityPublic


 entityIdentification
Public EntityIdentification entityIdentification
Constraints:
Properties:

AggregationNone
Alias
AssociationSecurityThreatExploitReferences
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
NameentityIdentification
Name Expression
NamespaceSecurityThreatExploit
OppositesecurityVulnerability2
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::entityIdentification
Stereotype
Template Parameter
TypeEntityIdentification
Upper*
Upper Value(*)
VisibilityPublic


 exploitType
Public String exploitType

An enumerated list of threa exploit types, such as:

Software Flaw
Weak Security Control
Cross-scripting Exploit
User-interaction Dependent Tool

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
NameexploitType
Name Expression
NamespaceSecurityThreatExploit
Opposite
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::exploitType
Stereotype
Template Parameter
TypeString
Upper*
Upper Value(*)
VisibilityPublic


 name
Public String name

A human readable name given to the exploit

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity0..1
Namename
Name Expression
NamespaceSecurityThreatExploit
Opposite
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::name
Stereotype
Template Parameter
TypeString
Upper1
Upper Value(1)
VisibilityPublic


 reference
Public «baseType» URI reference

A reference to additional information about a threat exploit.

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower0
Lower Value(0)
Multiplicity*
Namereference
Name Expression
NamespaceSecurityThreatExploit
Opposite
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::reference
Stereotype
Template Parameter
Type«baseType» URI
Upper*
Upper Value(*)
VisibilityPublic


 unauthorizedResults
Public String unauthorizedResults

Description the unauthorized results obtained through the use of this exploit

Constraints:
Properties:

AggregationNone
Alias
Association
Association End
ClassSecurityThreatExploit
Datatype
Default
Default Value
Is Compositefalse
Is Derivedfalse
Is Derived Unionfalse
Is Leaffalse
Is Orderedfalse
Is Read Onlyfalse
Is Staticfalse
Is Uniquetrue
Keywords
Lower1
Lower Value
MultiplicityNone (1)
NameunauthorizedResults
Name Expression
NamespaceSecurityThreatExploit
Opposite
OwnerSecurityThreatExploit
Owning Association
Owning Template Parameter
Qualified NameSID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Threat ABE::SecurityThreatExploit::unauthorizedResults
Stereotype
Template Parameter
TypeString
Upper1
Upper Value
VisibilityPublic