S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Oct 7, 2026

MITRE Caldera Default Login Scanner

This scanner detects the use of MITRE Caldera in digital assets. It identifies instances that still accept the default operator credentials shipped with the insecure default configuration. Detecting this exposure early helps prevent a full takeover of the adversary-emulation server.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3
Times Used
continuous scan runs
3.3k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
Detail

MITRE Caldera is an open-source adversary-emulation and command-and-control framework. It is developed and maintained by MITRE as a platform for automated security testing. Red teams and penetration testers use it to emulate adversary behavior mapped to the MITRE ATT&CK knowledge base. It drives lightweight agents deployed on target hosts and runs abilities and full operations against them. Blue teams rely on it to validate and tune their detection and response capabilities. It is typically deployed as a self-hosted web application that operators reach through a browser-based console.

Caldera ships with a set of built-in operator accounts for its web console. When the server is started with its insecure default configuration, these accounts stay active with well-known static passwords. The scanner checks whether a reachable instance still accepts those default credentials. It targets the authentication flow that is shared by both the classic and the newer console. A successful login confirms that the deployment is left in an exposed state. This reflects a common misconfiguration where unique credentials are never set before the server is published.

The scanner first requests the login page to confirm that the target is a genuine Caldera instance. It then submits credentials to the /enter authentication endpoint using the username and password form parameters. Both the v4 classic console and the v5 Magma console expose this same endpoint. On a valid login the server issues an API_SESSION session cookie, which is used as the success signal. The default operator accounts red, blue, and admin are each attempted with the default password. The initial login-page fingerprint keeps the check scoped to Caldera and avoids false positives on unrelated applications.

Access through default credentials grants an attacker an authenticated session with full operator privileges on the console. From there the attacker can register agents, run abilities, and execute arbitrary commands on every connected host. Because Caldera is a command-and-control platform, this effectively hands the attacker a ready-made offensive infrastructure inside the environment. The result can be complete compromise of the managed hosts, lateral movement, and theft or destruction of sensitive data.

REFERENCES

Solution Advice
  • Replace the built-in red, blue, and admin accounts with unique operator accounts that use strong, unpredictable passwords.
  • Never run the server with the insecure default configuration in any environment that is reachable by others.
  • Restrict the console to trusted networks or place it behind a VPN or access proxy.
  • Rotate account passwords and the server session secret on a regular schedule.
  • Review the configured user list periodically and remove any account that is no longer needed.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.