Skip to content
Every technique
T1694.002Not expressible in SigmaICS

Hardcoded Credentials

Persistence · Lateral Movement

Where this stands

No Sigma rule can address this — the telemetry MITRE names has no Sigma logsource behind it.

Sigma has no logsource taxonomy for ICS. MITRE's telemetry here is operational historians and controller state, which no Sigma rule can address.

What the technique is

Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset. Examples credentials that may be hardcoded in an asset include: Username/Passwords Cryptographic keys/Certificates API tokens Unlike Default Credentials, these credentials are built into the system in a way that they either cannot be changed by the asset owner, or may be infeasible to change because of the impact it would cause to the control system operation. These credentials may be reused across whole product lines or device models and are often not published or known to the owner and operators of the asset. Adversaries may utilize these hardcoded credentials to move throughout the control system environment or provide reliable access for their tools to interact with industrial assets.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1930

    Monitor network traffic for hardcoded credential use in protocols that allow unencrypted authentication. Monitor logon sessions for hardcoded credential use, when feasible.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.