AML.T0012: Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access. Credentials may take the form of usernames and passwords of individual user accounts or API keys that provide access to various AI resources and services.
Compromised credentials may provide access to additional AI artifacts and allow the adversary to perform Discover AI Artifacts. Compromised credentials may also grant an adversary increased privileges such as write access to AI artifacts used during development or production.
Standards mapping
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is AML.T0012 Valid Accounts?
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access. Credentials may take the form of usernames and passwords of individual user accounts or API keys that provide access to various AI resources and services. Compromised credentials may provide access to additional AI artifacts and allow the adversary to perform Discover AI Artifacts. Compromised credentials may also grant an adversary increased privileges such as write access to AI artifacts used during development or production.
Which tactics does AML.T0012 belong to?
AML.T0012 maps to the Initial Access, Privilege Escalation tactics.
Does TurboPentest test for Valid Accounts?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related MITRE ATLAS techniques
- Initial AccessAML.T0010: AI Supply Chain Compromise
- Initial Access, Defense Evasion, ImpactAML.T0015: Evade AI Model
- Initial AccessAML.T0049: Exploit Public-Facing Application
- Initial Access, Lateral MovementAML.T0052: Phishing
- Initial AccessAML.T0078: Drive-by Compromise
- Initial Access, PersistenceAML.T0093: Prompt Infiltration via Public-Facing Application
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest