Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078.001

T1078.001Default Accounts

T1078.001 — Default Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 17 detection use cases covering it and 8 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
17Use cases
8Articles
0Sub-techniques
4Tactics

Use cases covering this technique (17)

Okta New API Token Created ESCU actions · alerting P Okta Phishing Detection with FastPass Origin Check ESCU actions · alerting P Okta Suspicious Activity Reported ESCU actions · alerting P Windows Guest Account Enabled Via Net.EXE ESCU actions · hunting P Multiple Okta Users With Invalid Credentials From The Same IP ESCU actions · alerting P Okta Account Lockout Events ESCU actions · hunting P Okta Failed SSO Attempts ESCU actions · hunting P Okta ThreatInsight Login Failure with High Unknown users ESCU actions · alerting P Okta ThreatInsight Suspected PasswordSpray Attack ESCU actions · alerting P [LLM] Telnet credential brute force against internet-exposed IoT/Linux devices (Tengu dropper entry) Bespoke delivery · alerting DSP [LLM] Successful IPMI/BMC login from unexpected source using default ADMIN/root accounts Bespoke actions · hunting SPDD [LLM] Pheditor default-credential exploitation traffic: POST to /pheditor.php from external source Bespoke delivery · hunting SΣP [LLM] Kimai forged Symfony login-link request (user+expires+hash signed URL) to super_admin Bespoke exploit · hunting SΣP [LLM] SiYuan kernel config (conf.json) written — audit for empty/missing AccessAuthCode Bespoke recon · hunting DSΣPDDCS [LLM] fast-mcp-telegram traversal token in request URL (URL-auth middleware) CVE-2026-52830 Bespoke exploit · alerting SP [LLM] FortiGate jsconsole / loopback admin login (CVE-2024-55591 auth-bypass exploitation) Bespoke exploit · alerting SP [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (8)