Adversaries may steal the credentials of a specific user or service account using credential access techniques. In some cases, default credentials for control system devices may be publicly available. Compromised credentials may be used to bypass access controls placed on various resources on hosts and within the network, and may even be used for persistent access to remote systems. Compromised and default credentials may also grant an adversary increased privilege to specific systems and devices or access to restricted areas of the network. Adversaries may choose not to use malware or tools, in conjunction with the legitimate access those credentials provide, to make it harder to detect their presence or to control devices and send legitimate commands in an unintended way. Adversaries may also create accounts, sometimes using predefined account names and passwords, to provide a means of backup access for persistence. (Citation: Booz Allen Hamilton) The overlap of credentials and permissions across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) and possibly between the enterprise and operational technology environments. Adversaries may be able to leverage valid credentials from one system to gain access to another system.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Switch
is related to Safety Controller
is related to Jump Host
is related to Field I/O
is related to Application Server
is related to Data Gateway
is related to Firewall
is related to Programmable Logic Controller (PLC)
is related to Intelligent Electronic Device (IED)
is related to Human-Machine Interface (HMI)
is related to Distributed Control System (DCS) Controller
is related to Control Server
is related to Workstation
is related to Virtual Private Network (VPN) Server
is related to Data Historian
is related to Remote Terminal Unit (RTU)
is related to Programmable Automation Controller (PAC)
is part of Lateral Movement
is blocked by Access Management
is blocked by Privileged Account Management
is blocked by User Account Management
is blocked by Detection of Valid Accounts
is blocked by Filter Network Traffic
is blocked by Multi-factor Authentication
is blocked by Password Policies
is blocked by Application Developer Guidance
is blocked by Audit
is blocked by Account Use Policies
is blocked by Active Directory Configuration
Impressum Deutsch Englisch