Esc
Default Accounts - T1078.001
(ATT&CK® Technique)
Definition
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS and the default service account in Kubernetes.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.
graph LR; T1078001["Default Accounts"] --> |uses| UserAccount["User Account"]; class T1078001 OffensiveTechniqueNode; class UserAccount ArtifactNode; click UserAccount href "/dao/artifact/d3f:UserAccount"; click T1078001 href "/offensive-technique/attack/T1078.001/"; click UserAccount href "/dao/artifact/d3f:UserAccount"; T1078001["Default Accounts"] --> |uses| DefaultUserAccount["Default User Account"]; class T1078001 OffensiveTechniqueNode; class DefaultUserAccount ArtifactNode; click DefaultUserAccount href "/dao/artifact/d3f:DefaultUserAccount"; click T1078001 href "/offensive-technique/attack/T1078.001/"; click DefaultUserAccount href "/dao/artifact/d3f:DefaultUserAccount"; AgentAuthentication["Agent Authentication"] --> | strengthens | DefaultUserAccount["Default User Account"]; AgentAuthentication["Agent Authentication"] -.-> | may-harden | T1078001["Default Accounts"] ; class AgentAuthentication DefensiveTechniqueNode; class DefaultUserAccount ArtifactNode; click AgentAuthentication href "/technique/d3f:AgentAuthentication"; AgentAuthentication["Agent Authentication"] --> | strengthens | UserAccount["User Account"]; class AgentAuthentication DefensiveTechniqueNode; class UserAccount ArtifactNode; click AgentAuthentication href "/technique/d3f:AgentAuthentication"; UnlockAccount["Unlock Account"] --> | restores | UserAccount["User Account"]; UnlockAccount["Unlock Account"] -.-> | may-restore | T1078001["Default Accounts"] ; class UnlockAccount DefensiveTechniqueNode; class UserAccount ArtifactNode; click UnlockAccount href "/technique/d3f:UnlockAccount"; UnlockAccount["Unlock Account"] --> | restores | DefaultUserAccount["Default User Account"]; class UnlockAccount DefensiveTechniqueNode; class DefaultUserAccount ArtifactNode; click UnlockAccount href "/technique/d3f:UnlockAccount"; UserAccountPermissions["User Account Permissions"] --> | restricts | DefaultUserAccount["Default User Account"]; UserAccountPermissions["User Account Permissions"] -.-> | may-isolate | T1078001["Default Accounts"] ; class UserAccountPermissions DefensiveTechniqueNode; class DefaultUserAccount ArtifactNode; click UserAccountPermissions href "/technique/d3f:UserAccountPermissions"; RestoreUserAccountAccess["Restore User Account Access"] --> | restores | UserAccount["User Account"]; RestoreUserAccountAccess["Restore User Account Access"] -.-> | may-restore | T1078001["Default Accounts"] ; class RestoreUserAccountAccess DefensiveTechniqueNode; class UserAccount ArtifactNode; click RestoreUserAccountAccess href "/technique/d3f:RestoreUserAccountAccess"; RestoreUserAccountAccess["Restore User Account Access"] --> | restores | DefaultUserAccount["Default User Account"]; class RestoreUserAccountAccess DefensiveTechniqueNode; class DefaultUserAccount ArtifactNode; click RestoreUserAccountAccess href "/technique/d3f:RestoreUserAccountAccess"; AccountLocking["Account Locking"] --> | disables | UserAccount["User Account"]; AccountLocking["Account Locking"] -.-> | may-evict | T1078001["Default Accounts"] ; class AccountLocking DefensiveTechniqueNode; class UserAccount ArtifactNode; click AccountLocking href "/technique/d3f:AccountLocking"; AccountLocking["Account Locking"] --> | disables | DefaultUserAccount["Default User Account"]; class AccountLocking DefensiveTechniqueNode; class DefaultUserAccount ArtifactNode; click AccountLocking href "/technique/d3f:AccountLocking"; UserAccountPermissions["User Account Permissions"] --> | restricts | UserAccount["User Account"]; class UserAccountPermissions DefensiveTechniqueNode; class UserAccount ArtifactNode; click UserAccountPermissions href "/technique/d3f:UserAccountPermissions";