> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-c/07-7-cwe-capec-attandck-atlas-and-weakness-to-attack-mapping.md).

# 7. CWE, CAPEC, ATT\&CK, ATLAS & weakness-to-attack mapping

## 7.1 CWE - Common Weakness Enumeration

<table><thead><tr><th width="87.9765625" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>CWE home</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cwe.mitre.org/">cwe.mitre.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Common Weakness Enumeration root. Provides standardized weakness taxonomy.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> CVE-to-CWE mappings are sometimes missing, broad, or imprecise.</td></tr><tr><td align="right">2</td><td><strong>CWE downloads</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cwe.mitre.org/data/downloads.html">cwe.mitre.org/data/downloads.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public downloads</td><td><strong><code>Relevance</code>:</strong> XML, CSV, archive bundles, &#x26; views for machine ingestion.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use downloadable structured data for robust taxonomy ingestion.</td></tr><tr><td align="right">3</td><td><strong>CWE latest PDF</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cwe.mitre.org/data/published/cwe_latest.pdf">cwe.mitre.org/data/published/cwe_latest.pdf</a><br><br><strong><code>Access / Cost</code>:</strong> Free public PDF</td><td><strong><code>Relevance</code>:</strong> PDF publication of latest CWE content.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Better for manual reference than automated ingestion.</td></tr><tr><td align="right">4</td><td><strong>CWE reports</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cwe.mitre.org/data/reports.html">cwe.mitre.org/data/reports.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Reports &#x26; curated views of CWE data.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for understanding categories, views, &#x26; prioritization.</td></tr><tr><td align="right">5</td><td><strong>CWE chains &#x26; composites</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cwe.mitre.org/data/reports/chains_and_composites.html">cwe.mitre.org/data/reports/chains_and_composites.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Describes weakness chains &#x26; composite weaknesses.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Important for modeling multi-step root causes &#x26; compound vulnerabilities.</td></tr><tr><td align="right">6</td><td><strong>CWE schema docs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cwe.mitre.org/documents/schema/index.html">cwe.mitre.org/documents/schema/index.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Schema documentation for CWE data.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use for parser validation &#x26; taxonomy consistency.</td></tr><tr><td align="right">7</td><td>CWE data definitions</td><td><a href="https://cwe.mitre.org/data/definitions/1000.html">cwe.mitre.org/data/definitions/1000.html</a></td></tr><tr><td align="right">8</td><td>CWE Top 25</td><td><a href="https://cwe.mitre.org/top25/">cwe.mitre.org/top25</a></td></tr><tr><td align="right">9</td><td>CWE AI/ML category - CWE-1448</td><td><a href="https://cwe.mitre.org/data/definitions/1448.html">cwe.mitre.org/data/definitions/1448.html</a></td></tr><tr><td align="right">10</td><td>CWE AI Working Group</td><td><a href="https://cwe.mitre.org/community/working_groups.html">cwe.mitre.org/community/working_groups.html</a></td></tr></tbody></table>

## 7.2 CAPEC - attack patterns

<table><thead><tr><th width="86.01953125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>CAPEC home</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://capec.mitre.org/">capec.mitre.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Catalog of attack patterns used to exploit weaknesses.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> CAPEC bridges weakness taxonomy &#x26; attacker behavior patterns.</td></tr><tr><td align="right">2</td><td><strong>CAPEC downloads</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://capec.mitre.org/data/downloads.html">capec.mitre.org/data/downloads.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public downloads</td><td><strong><code>Relevance</code>:</strong> XML/CSV attack-pattern bundles.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Prefer structured downloads for ingestion.</td></tr><tr><td align="right">3</td><td><strong>CAPEC schema docs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://capec.mitre.org/documents/schema/index.html">capec.mitre.org/documents/schema/index.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Schema docs for CAPEC data.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Important for parser validation.</td></tr><tr><td align="right">4</td><td><strong>CAPEC data index</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://capec.mitre.org/data/index.html">capec.mitre.org/data/index.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Browsable CAPEC entries &#x26; views.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for manual mapping &#x26; explanation.</td></tr><tr><td align="right">5</td><td><strong>MITRE CTI repository - ATT&#x26;CK &#x26; CAPEC in STIX</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre/cti">github.com/mitre/cti</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> MITRE ATT&#x26;CK &#x26; CAPEC datasets expressed in STIX 2.0.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for graph-based relationships. May differ from newer ATT&#x26;CK-specific STIX repo content.</td></tr></tbody></table>

## 7.3 MITRE ATT\&CK

<table><thead><tr><th width="88.25390625" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>ATT&#x26;CK Enterprise Matrix</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://attack.mitre.org/matrices/enterprise/">attack.mitre.org/matrices/enterprise</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Enterprise adversary tactics &#x26; techniques.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> More relevant for adversary behavior after exploitation than raw CVE severity.</td></tr><tr><td align="right">2</td><td><strong>ATT&#x26;CK Matrices</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://attack.mitre.org/matrices/">attack.mitre.org/matrices</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> ATT&#x26;CK matrices across domains.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for selecting enterprise, mobile, ICS, or other domain views.</td></tr><tr><td align="right">3</td><td><strong>ATT&#x26;CK Data &#x26; Tools</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://attack.mitre.org/resources/attack-data-and-tools/">attack.mitre.org/resources/attack-data-and-tools</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> ATT&#x26;CK Navigator, STIX/TAXII, Workbench, &#x26; tooling references.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Prefer machine-readable STIX/TAXII for ingestion.</td></tr><tr><td align="right">4</td><td><strong>ATT&#x26;CK STIX data repo</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre-attack/attack-stix-data">github.com/mitre-attack/attack-stix-data</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Machine-readable ATT&#x26;CK STIX data.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Best source for automated technique/tactic ingestion.</td></tr><tr><td align="right">5</td><td><strong>MITRE CTI repository</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre/cti">github.com/mitre/cti</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> MITRE CTI STIX datasets.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Keep for historical/related STIX content.</td></tr><tr><td align="right">6</td><td><strong>ATT&#x26;CK Navigator</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://mitre-attack.github.io/attack-navigator/">mitre-attack.github.io/attack-navigator</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source web tool</td><td><strong><code>Relevance</code>:</strong> Visual mapping of techniques to campaigns, risks, or controls.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for reporting &#x26; matrix visualization, not raw vuln ingestion.</td></tr><tr><td align="right">7</td><td><strong>ATT&#x26;CK Workbench</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/center-for-threat-informed-defense/attack-workbench-frontend">github.com/center-for-threat-informed-defense/attack-workbench-frontend</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Tooling for ATT&#x26;CK customization &#x26; management.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for internal technique mapping workflows.</td></tr><tr><td align="right">8</td><td><strong>ATT&#x26;CK TAXII server docs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://attack.mitre.org/resources/attack-data-and-tools/">attack.mitre.org/resources/attack-data-and-tools</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> TAXII/STIX access docs.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Same source as ATT&#x26;CK Data &#x26; Tools; retained to preserve the explicit TAXII reference.</td></tr><tr><td align="right">9</td><td><strong>ATT&#x26;CK Sync</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/center-for-threat-informed-defense/attack-sync">github.com/center-for-threat-informed-defense/attack-sync</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Tooling for consuming MITRE ATT&#x26;CK version updates into internal systems &#x26; processes.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for keeping local ATT&#x26;CK technique mappings current.</td></tr><tr><td align="right">10</td><td><strong>MITRE ATT&#x26;CK Python</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre-attack/mitreattack-python">github.com/mitre-attack/mitreattack-python</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Python module for working with ATT&#x26;CK datasets.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for programmatic ATT&#x26;CK ingestion, transformation, &#x26; analysis.</td></tr><tr><td align="right">11</td><td><strong>ATT&#x26;CK Navigator GitHub repo</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre-attack/attack-navigator">github.com/mitre-attack/attack-navigator</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Source repository for the ATT&#x26;CK Navigator web app.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Complements the hosted Navigator URL; useful for local customization &#x26; offline visualization workflows.</td></tr></tbody></table>

## 7.4 AI/ML-specific adversary frameworks

<table><thead><tr><th width="87.05078125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>MITRE ATLAS</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://atlas.mitre.org/">atlas.mitre.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Living knowledge base of adversary tactics &#x26; techniques against AI-enabled systems.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> More directly relevant to AI systems than ATT&#x26;CK Enterprise alone.</td></tr><tr><td align="right">2</td><td><strong>MITRE ATLAS matrix</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://atlas.mitre.org/matrices/ATLAS">atlas.mitre.org/matrices/ATLAS</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Matrix view of AI adversary tactics &#x26; techniques.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for AI threat modeling &#x26; impact mapping.</td></tr><tr><td align="right">3</td><td><strong>MITRE ATLAS techniques</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://atlas.mitre.org/techniques">atlas.mitre.org/techniques</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Technique-level ATLAS entries.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use for structured AI attack technique mapping.</td></tr><tr><td align="right">4</td><td><strong>MITRE ATLAS case studies</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://atlas.mitre.org/studies">atlas.mitre.org/studies</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Case studies of AI attacks &#x26; failures.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Helpful for real-world analogs &#x26; model training examples.</td></tr><tr><td align="right">5</td><td><strong>MITRE ATLAS data repository / case-study data</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre-atlas/atlas-data">github.com/mitre-atlas/atlas-data</a>, <a href="https://github.com/mitre-atlas/atlas-data/tree/main/data/case-studies">case studies</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Structured ATLAS data, including case-study material.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Prefer this for machine-readable ATLAS case-study ingestion.</td></tr><tr><td align="right">6</td><td><strong>MITRE ATLAS GitHub / Adversarial ML Threat Matrix</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre/advmlthreatmatrix">github.com/mitre/advmlthreatmatrix</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Historical &#x26; structured project data for adversarial ML threat matrix.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> May not be the most current ATLAS view; keep for lineage.</td></tr><tr><td align="right">7</td><td><strong>MITRE SAFE-AI report</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://atlas.mitre.org/pdf-files/SAFEAI_Full_Report.pdf">atlas.mitre.org/pdf-files/SAFEAI_Full_Report.pdf</a><br><br><strong><code>Access / Cost</code>:</strong> Free public PDF</td><td><strong><code>Relevance</code>:</strong> AI system risk mapping across model, data, platform, &#x26; environment layers.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for AI-specific control mapping &#x26; architecture risk analysis.</td></tr><tr><td align="right">8</td><td><strong>OWASP Top 10 for LLM Applications</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/">owasp.org/www-project-top-10-for-large-language-model-applications</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source community project</td><td><strong><code>Relevance</code>:</strong> Practical LLM application vulnerability taxonomy.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for AI appsec detection categories beyond CVE.</td></tr><tr><td align="right">9</td><td><strong>OWASP Top 10 for Machine Learning Security</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://owasp.org/www-project-machine-learning-security-top-10/">owasp.org/www-project-machine-learning-security-top-10</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source community project</td><td><strong><code>Relevance</code>:</strong> ML-specific application/security risk taxonomy.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Complements ATLAS with appsec-oriented framing.</td></tr><tr><td align="right">10</td><td><strong>OWASP AI Exchange</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://owaspai.org/">owaspai.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public community resource</td><td><strong><code>Relevance</code>:</strong> AI security risks, controls, &#x26; threat modeling references.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for governance &#x26; risk mapping.</td></tr><tr><td align="right">11</td><td><strong>NIST AI Risk Management Framework</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.nist.gov/itl/ai-risk-management-framework">www.nist.gov/itl/ai-risk-management-framework</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> AI risk management framework.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for risk controls, governance, &#x26; impact framing.</td></tr><tr><td align="right">12</td><td><strong>NIST AI RMF 1.0 PDF</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf">nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf</a><br><br><strong><code>Access / Cost</code>:</strong> Free public PDF</td><td><strong><code>Relevance</code>:</strong> AI RMF 1.0 document.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> PDF reference; not a vulnerability feed.</td></tr><tr><td align="right">13</td><td><strong>NIST AI 600-1 - Generative AI Profile</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence">www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> GenAI risk profile companion to AI RMF.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for LLM/generative AI-specific risk categories.</td></tr><tr><td align="right">14</td><td><strong>NIST adversarial machine learning taxonomy</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.nist.gov/publications/adversarial-machine-learning-taxonomy-and-terminology-attacks-and-mitigations">www.nist.gov/publications/adversarial-machine-learning-taxonomy-and-terminology-attacks-and-mitigations</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Taxonomy &#x26; terminology for adversarial ML attacks &#x26; mitigations.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Good for consistent AI vulnerability vocabulary.</td></tr><tr><td align="right">15</td><td><strong>MLCommons AI Safety</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://mlcommons.org/working-groups/ai-safety/">mlcommons.org/working-groups/ai-safety</a><br><br><strong><code>Access / Cost</code>:</strong> Free public community resource</td><td><strong><code>Relevance</code>:</strong> AI safety benchmarks &#x26; working group context.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for AI system risk evaluation, not direct CVE matching.</td></tr><tr><td align="right">16</td><td><strong>MITRE ATLAS AI Risk Database</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/mitre-atlas/ai-risk-database">github.com/mitre-atlas/ai-risk-database</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> AI supply-chain risk database associated with MITRE ATLAS ecosystem work.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for AI-specific supply-chain risk analysis &#x26; case-study style enrichment.</td></tr><tr><td align="right">17</td><td><strong>Cisco AI Defense Skill Scanner</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/cisco-ai-defense/skill-scanner">github.com/cisco-ai-defense/skill-scanner</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Security scanner for agent skills.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for AI-agent/tooling security review, prompt/tool-surface assessment, &#x26; skill-level exposure analysis.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-c/07-7-cwe-capec-attandck-atlas-and-weakness-to-attack-mapping.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
