| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | 
|---|---|---|---|---|
| action.malware.vector.Web application - drive-by | Web via auto-executed or "drive-by" infection. Child of 'Web application'. | related-to | T1176 | Browser Extensions | 
| action.malware.vector.Web application - drive-by | Web via auto-executed or "drive-by" infection. Child of 'Web application'. | related-to | T1189 | Drive-by Compromise | 
| action.malware.vector.Web application - drive-by | Web via auto-executed or "drive-by" infection. Child of 'Web application'. | related-to | T1212 | Exploitation for Credential Access |