Skip to content
← LibraryTechnique entry
W-AUTH-DEFAULTCredential Access

Default Credentials

Vendor-shipped admin/admin, root/calvin, etc. on appliance UIs and installed apps (Tomcat manager, Jenkins, GLPI, …).

§ Where this technique fits

W-AUTH-DEFAULT is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 4 approved dossiers in the registry, typically at step 2.8 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    ArgoCD Misconfigured RBAC
    CI-ARGOCD-TAKEOVER · Privilege Escalation
    seen 1×
  2. 02
    Jenkins Script Console RCE
    CI-PIPELINE-RCE · Execution
    seen 1×
  3. 03
    MFP LDAP Address-Book Credential Theft
    PRT-LDAP-CRED-STEAL · Credential Access
    seen 1×
  4. 04
    OTA Update MITM
    IOT-OTA-MITM · Initial Access
    seen 1×