Change Default Password
Definition
Changing the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access.
How it works
Change the default password as soon as a new device is received. The default credentials are normally documented in an instruction manual that is either packaged with the device, published online through official means, or published online through unofficial means.
Considerations
- These should be changed before a device is brought online so that an adversary cannot take advantage of these default credentials.
- Strong and complex passwords are preferred if the technology allows.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related ATT&CK Techniques:
These offensive techniques are determined related because of the way this defensive technique,, , , and .
References
The following references were used to develop the Change Default Password knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)