Insecure Credentials
Description
Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another. Insecure credentials may appear as default credentials which are pre-configured credentials on a system, device, or software that are well-known in documentation or hard-coded credentials which are built into the system, device, or software that cannot be changed or not easily changed because of the impact on control processes.(Citation: NIST SP 800-82r3)(Citation: ICS-ALERT-13-164-01)(Citation: OT IceFall) Adversaries often times use insecure credentials to evade detection as they are typically forgotten about by system and device owners.
Mapped SPARTA techniques
1 techniques
T1694 'Insecure Credentials' is in lateral-movement tactic and covers leveraging pre-existing insecure credentials (default, hardcoded) for traversal; SPARTA LM-0007 includes use of weak/captured credentials as one of its mechanisms. Tactic-aligned but moderate because LM-0007 is broader (covers any credentialed traversal, not just insecure-credential abuse).
Cite as SafeMode Space, mitre-attack-ics T1694.