Finding Known Default Credentials
Many breaches start with a password that was never changed from the factory setting. Analog Informatics Corporation (AIC) kits find systems and devices on your network, match each one to published vendor default credentials, and flag the ones that still use a dangerous default so they can be changed.

This is built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits. In industry terms it is part of identity security posture management (ISPM).
Short Answers
What does the kit look for?
Where do the default credential lists come from?
How does it find the devices?
Does it try a default password on every device?
What happens when a default is found?
Is the scanner's cryptography validated?
What Is Covered
Capability
- IPv4 and IPv6 network scan with port profiles and custom port lists
- Editable catalog of known default credentials
- Bundled dictionaries from licensed public sources, with reload and fetch-latest
- Customer-supplied dictionaries
- Platform password patterns
- Signature matching to catalog entries
- Skip when a working non-default credential is already known
- "Dangerous default" flag on the Systems List
- Operational technology (OT) and network device checks
- Vulnerability analysis of discovered systems
Scan only networks and systems you own or are authorized to assess.
Screenshots
Related Controls
| Framework | Controls |
|---|---|
| NIST SP 800-53 | IA-5, CM-6, CM-8, RA-5 |
| NIST SP 800-171 | 3.4.1, 3.5.7, 3.11.2 |
| CMMC | CM.L2-3.4.1, IA.L2-3.5.7 |
| IEC 62443 | SR 1.5 (authenticator management) |
An assessment organization, and in some cases the government, decides whether an organization meets a framework.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.