Compliance Node Overview
MITRE ATT&CK ICS T1694.001 (Default Credentials) is an ICS Persistence, Lateral Movement technique. Adversaries may leverage manufacturer or supplier set default credentials on control system devices. These default credentials may have administrative permissions and may be necessary for initial configuration of the device. It is general best practice to change the passwords for these accounts as soon as possible, but some manufacturers may have devices that have passwords or usernames that cannot be changed. Default credentials are normally documented in an instruction manual that is either packaged with the device, published online through official means, or published online through unofficial means. Adversaries may leverage default credentials that have not been properly modified or disabled. Affected platforms: see ATT&CK ICS. Sub-technique of ATT&CK T1694. ATT&CK-mapped mitigations: M0927 Password Policies, M0801 Access Management.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1694/001/
SHA-256 integrity: 014fcdb9c74309f6bd36451f888ef77404f89c089df32059f3c79910a77275d9
Primary Citations — 8 traced to source
- MITRE ATT&CK ICS Technique T1694.001: Default Credentials (https://attack.mitre.org/techniques/T1694/001/)
- MITRE ATT&CK ICS Tactic TA0110: Persistence (https://attack.mitre.org/tactics/TA0110/)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.