AML.T0012: Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access. Credentials may take the form of usernames and passwords of individual user accounts or API keys that provide access to various AI resources and services.
Compromised credentials may provide access to additional AI artifacts and allow the adversary to perform Discover AI Artifacts. Compromised credentials may also grant an adversary increased privileges such as write access to AI artifacts used during development or production.
Standards mapping
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is AML.T0012 Valid Accounts?
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access. Credentials may take the form of usernames and passwords of individual user accounts or API keys that provide access to various AI resources and services. Compromised credentials may provide access to additional AI artifacts and allow the adversary to perform Discover AI Artifacts. Compromised credentials may also grant an adversary increased privileges such as write access to AI artifacts used during development or production.
Which tactics does AML.T0012 belong to?
AML.T0012 maps to the Initial Access, Privilege Escalation tactics.
Does TurboPentest test for Valid Accounts?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related MITRE ATLAS techniques
- Initial AccessAML.T0010: AI Supply Chain Compromise
- Initial Access, Defense Evasion, ImpactAML.T0015: Evade AI Model
- Initial AccessAML.T0049: Exploit Public-Facing Application
- Initial Access, Lateral MovementAML.T0052: Phishing
- Initial AccessAML.T0078: Drive-by Compromise
- Initial Access, PersistenceAML.T0093: Prompt Infiltration via Public-Facing Application
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest