Insecure Credentials
Where this stands
No Sigma rule can address this — the telemetry MITRE names has no Sigma logsource behind it.
Sigma has no logsource taxonomy for ICS. MITRE's telemetry here is operational historians and controller state, which no Sigma rule can address.
What the technique is
Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another. Insecure credentials may appear as default credentials which are pre-configured credentials on a system, device, or software that are well-known in documentation or hard-coded credentials which are built into the system, device, or software that cannot be changed or not easily changed because of the impact on control processes. Adversaries often times use insecure credentials to evade detection as they are typically forgotten about by system and device owners.
Read it on attack.mitre.orgWhat MITRE says you would watch
- AN2048
Monitor network traffic for insecure credential use in protocols that allow unencrypted authentication. Monitor logon sessions for insecure credential use, when feasible.
Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.