SCCM Abuse
System Center Configuration Manager / Microsoft Endpoint Configuration Manager
Enumeration
Look for CcmExec.exe processes:
Search for SCCM servers in LDAP:
VNC-like Remote Control (CmRcViewer Abuse)
Tools
MalSCCM
sccmwtf
SharpSCCM
Get SMS (Systems Management Server) and SC (Site Code):
List SCCM admins:
List user latest logons:
Get resource (server) ID:
Execute WMI command on a resource:
Grab secrets from SCCM client (locally):
Coerce authentication from SCCM server (remotely):
Last updated