AltaySec · ATLAS 2026.07
AML.T0012

Valid Accounts

C · Explainer (cannot be honestly simulated in-browser) AML.TA0004 · Initial Access AML.TA0012 · Privilege Escalation

Description

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access. Credentials may take the form of usernames and passwords of individual user accounts or API keys that provide access to various AI resources and services. Compromised credentials may provide access to additional AI artifacts and allow the adversary to perform Discover AI Artifacts. Compromised credentials may also grant an adversary increased privileges such as write access to AI artifacts used during development or production.

Honesty-tier rationale

Requires real infrastructure, valid credentials, or a victim. Working access cannot be honestly enacted inside a browser.

Source

← Back to the matrix