SCCM Abuse

System Center Configuration Manager / Microsoft Endpoint Configuration Manager

Enumeration

Look for CcmExec.exe processes:

Search for SCCM servers in LDAP:

VNC-like Remote Control (CmRcViewer Abuse)

Tools

MalSCCM

sccmwtf

SharpSCCM

Get SMS (Systems Management Server) and SC (Site Code):

List SCCM admins:

List user latest logons (automated in sccmhound):

Get resource (server) ID:

Execute WMI command on a resource:

Grab secrets from SCCM client (locally):

Coerce authentication from SCCM server (remotely):

sccmhunter

Install:

List user latest logons:

Last updated