Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078.001

T1078.001Default Accounts

T1078.001 — Default Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 19 detection use cases covering it and 8 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
19Use cases
8Articles
0Sub-techniques
4Tactics

Use cases covering this technique (19)

Okta New API Token Created ESCU actions · alerting P Okta Phishing Detection with FastPass Origin Check ESCU actions · alerting P Okta Suspicious Activity Reported ESCU actions · alerting P Windows Guest Account Enabled Via Net.EXE ESCU actions · hunting P Multiple Okta Users With Invalid Credentials From The Same IP ESCU actions · alerting P Okta Account Lockout Events ESCU actions · hunting P Okta Failed SSO Attempts ESCU actions · hunting P Okta ThreatInsight Login Failure with High Unknown users ESCU actions · alerting P Okta ThreatInsight Suspected PasswordSpray Attack ESCU actions · alerting P [LLM] SAP Commerce Cloud CVE-2026-58231: default OAuth client abuse against Data Hub Adapter Bespoke exploit · hunting SΣP [LLM] NocoBase anonymous account sign-up via auth-basic (allowSignUp) exploitation prerequisite Bespoke delivery · hunting SΣP [LLM] NocoBase sign-up immediately followed by myInAppChannels exploitation from same source Bespoke delivery · alerting SP [LLM] goshs launched with exploitable empty-credential SFTP config (CVE-2026-62325) Bespoke exploit · alerting DSΣPDDCS [LLM] goshs basic-auth flag with empty username or password (config-audit hunt) Bespoke exploit · hunting DSΣPDDCS [LLM] Privileged Gitea action correlated with client-supplied X-WEBAUTH-USER (CVE-2026-20896) Bespoke actions · alerting SP [LLM] Pheditor default-credential exploitation traffic: POST to /pheditor.php from external source Bespoke delivery · hunting SΣP [LLM] Kimai forged Symfony login-link request (user+expires+hash signed URL) to super_admin Bespoke exploit · hunting SΣP [LLM] SiYuan kernel config (conf.json) written — audit for empty/missing AccessAuthCode Bespoke recon · hunting DSΣPDDCS [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (8)