MITRE ATT&CK ICS
T0859

Valid Accounts

Description

Adversaries may steal the credentials of a specific user or service account using credential access techniques. In some cases, default credentials for control system devices may be publicly available. Compromised credentials may be used to bypass access controls placed on various resources on hosts and within the network, and may even be used for persistent access to remote systems. Compromised and default credentials may also grant an adversary increased privilege to specific systems and devices or access to restricted areas of the network. Adversaries may choose not to use malware or tools, in conjunction with the legitimate access those credentials provide, to make it harder to detect their presence or to control devices and send legitimate commands in an unintended way. Adversaries may also create accounts, sometimes using predefined account names and passwords, to provide a means of backup access for persistence. (Citation: Booz Allen Hamilton) The overlap of credentials and permissions across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) and possibly between the enterprise and operational technology environments. Adversaries may be able to leverage valid credentials from one system to gain access to another system.

Mapped SPARTA techniques

5 techniques

  • DE-0011Credentialed EvasionST0006
    addresses
    moderate

    T0859 'Valid Accounts' addresses adversary use of legitimate credentials so that detection systems treat actions as legitimate; SPARTA DE-0011 'Credentialed Evasion' is the same activity. Cross-tactic moderate (T0859 in persistence and lateral-movement; ICS doesn't list T0859 in defense-evasion explicitly — but the credentialed-evasion concept is the same as T0859's intent).

  • EXF-0007Compromised Ground SystemST0008
    addresses
    moderate

    Compromised-ground-system exfiltration uses the GS's legitimate operator credentials and access paths to siphon mission data over its existing data-distribution channels; T0859 'Valid Accounts' covers this credential-driven exfil pattern. Cross-tactic moderate (T0859 in persistence and lateral-movement vs SPARTA EXF-0007 exfiltration); ICS has no exfiltration tactic.

  • T0859 'Valid Accounts' is in MITRE ICS lateral-movement tactic and addresses adversary use of legitimate credentials to traverse systems; SPARTA LM-0007 'Credentialed Traversal' is exactly this activity for spacecraft (use captured TC keys, ground-system creds, or relay-station credentials to move between subsystems/sites). Tactic and activity align directly.

  • T0859 'Valid Accounts' is in MITRE ICS persistence tactic and addresses adversary use of valid credentials for persistent access; SPARTA PER-0003 'Ground System Presence' covers persistent attacker access on operator workstations / MOC servers via legitimate operator credentials. Tactic and activity align directly.

  • T0859 'Valid Accounts' is in MITRE ICS persistence tactic and addresses adversary use of legitimate credentials for persistent access; SPARTA PER-0005 'Credentialed Persistence' is the same activity in spacecraft/ground operator credential context. Tactic and activity align directly.

Cite as SafeMode Space, mitre-attack-ics T0859.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.