It's an interesting optimization problem for the attacker.
The most common passwords are problematic. They will frequently work, but they will work for the other guy, too. So then the question is "how do you pull up the ladder?"
Changing the password is simple, but likely to get the machine reimaged.
Looking at the login history would give an allowlist of subnets, which can be used to deny other attackers access, but hopefully without inconveniencing the owner into reimaging.