Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078.001

T1078.001Default Accounts

T1078.001 — Default Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 13 detection use cases covering it and 4 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
4Articles
0Sub-techniques
4Tactics

Use cases covering this technique (13)

Okta New API Token Created ESCU actions · alerting P Okta Phishing Detection with FastPass Origin Check ESCU actions · alerting P Okta Suspicious Activity Reported ESCU actions · alerting P Windows Guest Account Enabled Via Net.EXE ESCU actions · hunting P Multiple Okta Users With Invalid Credentials From The Same IP ESCU actions · alerting P Okta Account Lockout Events ESCU actions · hunting P Okta Failed SSO Attempts ESCU actions · hunting P Okta ThreatInsight Login Failure with High Unknown users ESCU actions · alerting P Okta ThreatInsight Suspected PasswordSpray Attack ESCU actions · alerting P [LLM] DbGate anonymous auth-bypass token mint — POST /auth/login with amoid:none Bespoke recon · hunting SΣPDD [LLM] Container default credential leak — PKP_DB_PASSWORD=changeMePlease and --secret Bespoke weapon · hunting DSΣPDDCS [LLM] Arcane GitOps: non-admin PUT on /api/customize/git-repositories/{id} followed by /test, /branches, or /files within 5 min (CVE-2026-45625 cr Bespoke actions · alerting SPDD [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (4)