Skip to content
Every technique
T1694Not expressible in SigmaICS

Insecure Credentials

Persistence · Lateral Movement

Where this stands

No Sigma rule can address this — the telemetry MITRE names has no Sigma logsource behind it.

Sigma has no logsource taxonomy for ICS. MITRE's telemetry here is operational historians and controller state, which no Sigma rule can address.

What the technique is

Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another. Insecure credentials may appear as default credentials which are pre-configured credentials on a system, device, or software that are well-known in documentation or hard-coded credentials which are built into the system, device, or software that cannot be changed or not easily changed because of the impact on control processes. Adversaries often times use insecure credentials to evade detection as they are typically forgotten about by system and device owners.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN2048

    Monitor network traffic for insecure credential use in protocols that allow unencrypted authentication. Monitor logon sessions for insecure credential use, when feasible.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.