跳到正文
FunCoding

搜索

搜索文档、文章、Skill 和 MCP

Initial access (AML.TA0004)

OpenClaw initial access threats (AML.TA0004): T-ACCESS-001, T-ACCESS-002, T-ACCESS-003

Threats in the initial access tactic (AML.TA0004) of the MITRE ATLAS framework. Each entry lists the ATLAS technique, attack vector, affected components, current mitigations, residual risk, and recommendations.

The trust boundaries and data flows these threats cross are defined in the threat model index, which also holds the risk matrix, the recommendations summary, and the ATLAS technique mapping.

T-ACCESS-001: Pairing code interception

AttributeValue
ATLAS IDAML.T0040 - AI Model Inference API Access
DescriptionAttacker intercepts a pairing code during the pairing window (1h DM/generic pairing, 5m node pairing)
Attack vectorShoulder surfing, network sniffing, social engineering
Affected componentsDevice pairing system
Current mitigations1h TTL (DM/generic pairing), 5m TTL (node pairing); codes sent via the existing channel
Residual riskMedium - pairing window exploitable
RecommendationsReduce pairing window, add a confirmation step

T-ACCESS-002: AllowFrom spoofing

AttributeValue
ATLAS IDAML.T0040 - AI Model Inference API Access
DescriptionAttacker spoofs an allowed sender identity on a channel
Attack vectorChannel-dependent - phone number spoofing, username impersonation
Affected componentsPer-channel AllowFrom validation
Current mitigationsChannel-specific identity verification; graded identifier-authentication gate uses min(entry, subject) over verified > asserted > unverified > mutable with exact match provenance and default minimum asserted (#123782/#123793). Channels declare per-identifier strength; security audit warns on inert mutable entries (#131129).
Residual riskMedium - some channels remain vulnerable to spoofing
RecommendationsContinue per-channel verified adoption and downstream strength mappers; document channel-specific risks

T-ACCESS-003: Token theft

AttributeValue
ATLAS IDAML.T0040 - AI Model Inference API Access
DescriptionAttacker steals authentication tokens from config/credential files
Attack vectorMalware, unauthorized device access, config backup exposure
Affected componentsChannel/provider credential storage, config storage
Current mitigationsFile permissions
Residual riskHigh - tokens stored in plaintext on disk
RecommendationsImplement token encryption at rest, add token rotation