Sccm Exploitation

Enumerates and exploits Microsoft SCCM/MECM (System Center Configuration Manager / Microsoft Endpoint Configuration Manager) infrastructure for credential harvesting, lateral movement, and domain escalation. Covers SCCM enumeration (sccmhunter, SharpSCCM), Network Access Account (NAA) credential extraction (policy request, WMI DPAPI, WMI repository), management point NTLM relay to MSSQL (TAKEOVER1), client push relay (ELEVATE2), PXE boot media credential harvesting (CRED1), SCCM database credential extraction, application deployment for lateral movement, and SCCM share looting.

blacklanternsecurity 50daa39 16.9 KB Updated

File contents

blacklanternsecurity/red-run/tree/main/skills/ad/sccm-exploitation commit 50daa39e96

Frequently asked questions

npx skillmds@latest add blacklanternsecurity/sccm-exploitation