MITRE ATT&CK ICS
T0892

Change Credential

Description

Adversaries may modify software and device credentials to prevent operator and responder access. Depending on the device, the modification or addition of this password could prevent any device configuration actions from being accomplished and may require a factory reset or replacement of hardware. These credentials are often built-in features provided by the device vendors as a means to restrict access to management interfaces. An adversary with access to valid or hardcoded credentials could change the credential to prevent future authorized device access. Change Credential may be especially damaging when paired with other techniques such as Modify Program, Data Destruction, or Modify Controller Tasking. In these cases, a device’s configuration may be destroyed or include malicious actions for the process environment, which cannot not be removed through normal device configuration actions. Additionally, recovery of the device and original configuration may be difficult depending on the features provided by the device. In some cases, these passwords cannot be removed onsite and may require that the device be sent back to the vendor for additional recovery steps. A chain of incidents occurred in Germany, where adversaries locked operators out of their building automation system (BAS) controllers by enabling a previously unset BCU key. (Citation: German BAS Lockout Dec 2021)

Mapped SPARTA techniques

2 techniques

  • T0892 'Change Credential' addresses adversary modification of credentials and credential-related software/configuration; SPARTA EX-0003 'Modify Authentication Process' is the broader auth-mechanism modification at cross-tactic level. Cross-tactic moderate (T0892 sits in inhibit-response-function while SPARTA EX-0003 is execution); concept-adjacent but not perfectly aligned (T0892 is credential-change-specific while SPARTA EX-0003 includes broader auth-process modifications).

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    moderate

    T0892 'Change Credential' addresses adversary modification of credentials and credential-related software/configuration; SPARTA PER-0004 'Replace Cryptographic Keys' is the same activity applied to spacecraft-command-channel cryptographic credentials (replace TC auth keys, KEKs, session keys to retain attacker access). Cross-tactic moderate (T0892 in inhibit-response-function vs SPARTA PER-0004 persistence); exact concept match.

Cite as SafeMode Space, mitre-attack-ics T0892.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.