MITRE ATT&CK ICS
T1694

Insecure Credentials

Description

Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another. Insecure credentials may appear as default credentials which are pre-configured credentials on a system, device, or software that are well-known in documentation or hard-coded credentials which are built into the system, device, or software that cannot be changed or not easily changed because of the impact on control processes.(Citation: NIST SP 800-82r3)(Citation: ICS-ALERT-13-164-01)(Citation: OT IceFall) Adversaries often times use insecure credentials to evade detection as they are typically forgotten about by system and device owners.

Mapped SPARTA techniques

1 techniques

  • LM-0007Credentialed TraversalST0007
    addresses
    moderate

    T1694 'Insecure Credentials' is in lateral-movement tactic and covers leveraging pre-existing insecure credentials (default, hardcoded) for traversal; SPARTA LM-0007 includes use of weak/captured credentials as one of its mechanisms. Tactic-aligned but moderate because LM-0007 is broader (covers any credentialed traversal, not just insecure-credential abuse).

Cite as SafeMode Space, mitre-attack-ics T1694.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.