mirror of
https://github.com/subat0mik/Misconfiguration-Manager
synced 2026-06-08 17:38:34 +00:00
SCCM Matrix and technique documentation updates
This commit is contained in:
@@ -22,7 +22,7 @@
|
||||

|
||||
|
||||
# Remediation Quick Start
|
||||
1. Review the list of known and documented [Attack Techniques](./attack-techniques/_attack-techniques-list.md) and corresponding [Defense Techniques](./defense-techniques/_defense-techniques-list.md) to identify issues that may be present in your environment and how to remediate them
|
||||
1. Review the list of known and documented [Attack Techniques](./attack-techniques/README.md) and corresponding [Defense Techniques](./defense-techniques/README.md) to identify issues that may be present in your environment and how to remediate them
|
||||
- Refer to this [introduction to the project](https://www.youtube.com/watch?v=GhT6nPes1h0&t=12s&pp=ygUYbWlzY29uZmlndXJhdGlvbiBtYW5hZ2Vy)
|
||||
2. Run [ConfigManBearPig](https://github.com/SpecterOps/ConfigManBearPig) and visualize the results in [BloodHound](https://github.com/SpecterOps/BloodHound) for free
|
||||
- Refer to this [walkthrough](https://specterops.io/blog/2026/01/13/introducing-configmanbearpig-a-bloodhound-opengraph-collector-for-sccm/)
|
||||
@@ -55,9 +55,9 @@ For more of an introduction to the project, please reference our blog and confer
|
||||
|
||||
Refer to the SCCM Attack Matrix and SCCM Attack and Defense Matrix below, which map attack techniques to their MITRE ATT&CK framework tactics, as well as to their detection and prevention strategies.
|
||||
|
||||
Offensive security practitioners may also benefit from reviewing the list of known and documented [Attack Techniques](./attack-techniques/_attack-techniques-list.md), which identifies the security context and network access that are required for each technique.
|
||||
Offensive security practitioners may also benefit from reviewing the list of known and documented [Attack Techniques](./attack-techniques/README.md), which identifies the security context and network access that are required for each technique.
|
||||
|
||||
Defenders and IT administrators may benefit from reviewing the list of known and documented [Defense Techniques](./defense-techniques/_defense-techniques-list.md), which identifies the administrator roles we think are most likely to be involved in the implementation of each item.
|
||||
Defenders and IT administrators may benefit from reviewing the list of known and documented [Defense Techniques](./defense-techniques/README.md), which identifies the administrator roles we think are most likely to be involved in the implementation of each item.
|
||||
|
||||
Curious about how a hierarchy can be completely compromised in certain, mostly default conditions? Check out the list of [TAKEOVER techniques](https://github.com/subat0mik/Misconfiguration-Manager/blob/main/attack-techniques/TAKEOVER/_takeover-techniques-list.md).
|
||||
|
||||
@@ -82,9 +82,9 @@ If we've overlooked anything or are missing credits for prior work, please reach
|
||||
| | | [Relay to LDAP](./attack-techniques/TAKEOVER/TAKEOVER-8/takeover-8_description.md) | [Relay to LDAP](./attack-techniques/TAKEOVER/TAKEOVER-8/takeover-8_description.md) | | [Legacy Credentials](./attack-techniques/CRED/CRED-4/cred-4_description.md) | [CMPivot](./attack-techniques/RECON/RECON-4/recon-4_description.md) | [App Deployment](./attack-techniques/EXEC/EXEC-1/exec-1_description.md) | | | |
|
||||
| | | | [Relay to Site DB (SMB)](./attack-techniques/TAKEOVER/TAKEOVER-2/takeover-2_description.md) | | [Site Database Credentials](./attack-techniques/CRED/CRED-5/cred-5_description.md) | [SMS Provider Enumeration](./attack-techniques/RECON/RECON-5/recon-5_description.md) | [Script Deployment](./attack-techniques/EXEC/EXEC-2/exec-2_description.md) | | | |
|
||||
| | | | [Relay to ADCS](./attack-techniques/TAKEOVER/TAKEOVER-3/takeover-3_description.md) | | [Client Push Installation Account](./attack-techniques/CRED/CRED-6/cred-6_description.md) | [Site Server Enumeration](./attack-techniques/RECON/RECON-6/recon-6_description.md) | [Relay to Site System (SMB)](./attack-techniques/ELEVATE/ELEVATE-1/ELEVATE-1_description.md) | | | |
|
||||
| | | | [Relay CAS to Child](./attack-techniques/TAKEOVER/TAKEOVER-4/takeover-4_description.md) | | [Distribution Point Looting](./attack-techniques/CRED/CRED-6/cred-6_description.md) | [Local File Enumeration](./attack-techniques/RECON/RECON-7/recon-7_description.md) | [Relay Client Push Installation](./attack-techniques/ELEVATE/ELEVATE-2/ELEVATE-2_description.md) | | | |
|
||||
| | | | [Relay to AdminService](./attack-techniques/TAKEOVER/TAKEOVER-5/takeover-5_description.md) | | [AdminService API Credentials](./attack-techniques/CRED/CRED-7/cred-7_description.md) | | [Relay CAS to Child](./attack-techniques/TAKEOVER/TAKEOVER-4/takeover-4_description.md) | | | |
|
||||
| | | | [Relay to SMS Provider (SMB)](./attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md) | | [Policy Creds MP Relay](./attack-techniques/CRED/CRED-8/cred-8_description.md) | | [Relay to SMS Provider (SMB)](./attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md) | | | |
|
||||
| | | | [Relay CAS to Child](./attack-techniques/TAKEOVER/TAKEOVER-4/takeover-4_description.md) | | [Distribution Point Looting](./attack-techniques/CRED/CRED-6/cred-6_description.md) | [Local File Enumeration](./attack-techniques/RECON/RECON-7/recon-7_description.md) | [Relay Client Push Installation](./attack-techniques/ELEVATE/ELEVATE-2/ELEVATE-2_description.md) | | | |
|
||||
| | | | [Relay to AdminService](./attack-techniques/TAKEOVER/TAKEOVER-5/takeover-5_description.md) | | [AdminService API Credentials](./attack-techniques/CRED/CRED-7/cred-7_description.md) | | [Relay CAS to Child](./attack-techniques/TAKEOVER/TAKEOVER-4/takeover-4_description.md) | | | |
|
||||
| | | | [Relay to SMS Provider (SMB)](./attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md) | | [Policy Creds MP Relay](./attack-techniques/CRED/CRED-8/cred-8_description.md) | | [Relay to SMS Provider (SMB)](./attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md) | | | |
|
||||
| | | | [Relay Between HA](./attack-techniques/TAKEOVER/TAKEOVER-7/takeover-7_description.md) | | | | [SQL Linked as DBA](./attack-techniques/TAKEOVER/TAKEOVER-9/takeover-9_description.md) | | | |
|
||||
| | | | [SQL Linked as DBA](./attack-techniques/TAKEOVER/TAKEOVER-9/takeover-9_description.md) | | | | | | | |
|
||||
| | | | [Relay to Site DB (SMB)](./attack-techniques/TAKEOVER/TAKEOVER-2/takeover-2_description.md) | | | | | | | |
|
||||
@@ -94,43 +94,43 @@ If we've overlooked anything or are missing credits for prior work, please reach
|
||||
<br>
|
||||
|
||||
# SCCM Attack and Defense Matrix
|
||||
The SCCM Attack and Defense Matrix is maintained as a [CSV file](./SCCM_AttackDefenseMatrix.csv) for full-width viewing and as the authoritative source of truth on mappings.
|
||||
|
||||
| | CRED‑1 | CRED‑2 | CRED‑3 | CRED‑4 | CRED‑5 | CRED‑6 | CRED‑7 | CRED‑8. |ELEVATE‑1 | ELEVATE‑2 | ELEVATE‑3 | EXEC‑1 | EXEC‑2 | RECON‑1 | RECON‑2 | RECON‑3 | RECON‑4 | RECON‑5 | RECON‑6 | RECON‑7 | TAKEOVER‑1 | TAKEOVER‑2 | TAKEOVER‑3 | TAKEOVER‑4 | TAKEOVER‑5 | TAKEOVER‑6 | TAKEOVER‑7 | TAKEOVER‑8 | TAKEOVER‑9 |
|
||||
| :-------------------- | :-----------: | :-----------: | :-----------: | :-----------: | :-----------: | :-----------: | :-----------: | :--------------: | :--------------: | :--------------: | :--------------: | :-----------: | :-----------: | :------------: | :------------: | :------------: | :------------: | :------------: | :------------: | :------------: | :---------------: | :---------------: | :---------------: | :---------------: | :---------------: | :---------------: | :---------------: | :---------------: |:----------------: |
|
||||
| **CANARY‑1** | X | X | X | X | X | X | X | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **DETECT‑1** | | | | | | | | X | X | X | X | X | | | | | | | | | X | X | X | X | X | X | X | X | |
|
||||
| **DETECT‑2** | | | | | | | | | | | | | | X | | | | | | | | | | | | | | | |
|
||||
| **DETECT‑3** | | | | | | | | | | X | X | X | | | | | | | | | | | | | | | | | |
|
||||
| **DETECT‑4** | | | | | | | | | | | | X | | | | | | | | | | | | | | | | | |
|
||||
| **DETECT‑5** | | | | | | | | | | | | | | | | | X | X | | | X | X | | | | | | | |
|
||||
| **DETECT‑6** | | | | | | | | | | | | | | | | | X | X | | | X | X | | | | | | | |
|
||||
| **DETECT‑7** | X | | | | | | | | | | | | | X | | | | | | | | | | | | | | | |
|
||||
| **DETECT‑8** | X | | | | | | | | | | | | | | | | | | X | | | | | | | | | | |
|
||||
| **DETECT‑9** | | | | | | | | | | | | | | | | | | | | X | | | | | | | | | |
|
||||
| **PREVENT‑1** | | | | | | | | | | X | X | X | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑2** | | | | | | | | | | X | X | X | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑3** | X | X | X | X | | X | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑4** | | X | X | X | | X | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑5** | | | | | | | | | | X | X | X | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑6** | X | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑7** | X | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑8** | | X | | | | X | | | | X | | | | | | | | | | | | | | | | X | | | |
|
||||
| **PREVENT‑9** | | | | | | | | | | | | X | X | | | | | X | | | X | | | | | X | | | |
|
||||
| **PREVENT‑10** | | X | X | X | X | X | X | X | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑11** | | | | | | | | | | X | | | | | | | | | | | | | X | | | | | X | |
|
||||
| **PREVENT‑12** | | | | | | | | | X | X | X | X | | | | | | | | | | X | | X | | X | X | | |
|
||||
| **PREVENT‑13** | | | | | | | | | | | | | | | | | | | | | | | | | | | | X | |
|
||||
| **PREVENT‑14** | | | | | | | | X | | | | | | | | | | | | | X | | X | | X | | | | |
|
||||
| **PREVENT‑15** | | | | X | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑16** | | X | | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑17** | X | X | X | X | X | X | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑18** | | | | | X | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑19** | | | | | X | | | | | | | | | | | | | | | | | | | | | | | | X |
|
||||
| **PREVENT‑20** | | | | | X | | X | X | X | | | X | X | | X | X | X | X | | | X | X | X | X | X | X | X | X | |
|
||||
| **PREVENT‑21** | X | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| **PREVENT‑22** | | | | | | X | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
|
||||
---
|
||||
**Matrix current as of:** 2026-02-09
|
||||
| | CRED‑1 | CRED‑2 | CRED‑3 | CRED‑4 | CRED‑5 | CRED‑6 | CRED‑7 | CRED‑8 | ELEVATE‑1 | ELEVATE‑2 | ELEVATE‑3 | ELEVATE‑4 | ELEVATE‑5 | EXEC‑1 | EXEC‑2 | RECON‑1 | RECON‑2 | RECON‑3 | RECON‑4 | RECON‑5 | RECON‑6 | RECON‑7 | TAKEOVER‑1 | TAKEOVER‑2 | TAKEOVER‑3 | TAKEOVER‑4 | TAKEOVER‑5 | TAKEOVER‑6 | TAKEOVER‑7 | TAKEOVER‑8 | TAKEOVER‑9 |
|
||||
| ---------- | ------ | ------ | ------ | ------ | ------ | ------ | ------ | ------ | --------- | --------- | --------- | --------- | --------- | ------ | ------ | ------- | ------- | ------- | ------- | ------- | ------- | ------- | ---------- | ---------- | ---------- | ---------- | ---------- | ---------- | ---------- | ---------- | ---------- |
|
||||
| CANARY‑1 | X | X | X | X | X | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| DETECT‑1 | | | | | | | | X | X | X | X | | | | | | | | | | | | X | X | X | X | X | X | X | X | |
|
||||
| DETECT‑2 | | | | | | | | | | | | | | | | X | | | | | | | | | | | | | | | |
|
||||
| DETECT‑3 | | | | | | | | | X | X | X | | | | | | | | | | | | | | | | | | | | |
|
||||
| DETECT‑4 | | | | | | | | | | | | | | X | | | | | | | | | | | | | | | | | |
|
||||
| DETECT‑5 | | | | | | | | | | | | | | | | | | | X | X | | | X | X | | X | X | X | X | | |
|
||||
| DETECT‑6 | | | | | | | | | | | | | | | | | | | X | X | X | X | X | X | | X | X | X | X | | |
|
||||
| DETECT‑7 | X | | | | | | | | | | | X | X | | | X | | | | | | | | | | | | | | | |
|
||||
| DETECT‑8 | X | | | | | | | | | | | | | | | | | | | | X | | | | | | | | | | |
|
||||
| DETECT‑9 | | | | | | | | | | | | | | | | | | | | | | X | | | | | | | | | |
|
||||
| PREVENT‑1 | | | | | | | | | | X | X | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑2 | | | | | | | | | | X | X | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑3 | X | X | X | X | X | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑4 | | X | X | X | | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑5 | | | | | | | | | | X | X | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑6 | X | | | | | | | | | | | X | X | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑7 | X | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑8 | | X | | | | | | | | X | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑9 | | | | | | | | | | | | | | X | X | | | | X | X | | X | | | | | X | | | | |
|
||||
| PREVENT‑10 | X | X | X | X | X | X | X | X | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑11 | | | | | | | | | | X | | | | | | | | | | | | | | | X | | | | | X | |
|
||||
| PREVENT‑12 | | | | | | | | | X | X | X | | | | | | | | | | | | | X | | X | | X | X | | |
|
||||
| PREVENT‑13 | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | X | |
|
||||
| PREVENT‑14 | | | | | | | | X | | | | | | | | | | | | | | | X | | X | | | | | | |
|
||||
| PREVENT‑15 | | | | X | | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑16 | | X | | | | | | | | | | | | | | | | | | | | | | | | | | | | X | |
|
||||
| PREVENT‑17 | X | X | X | X | X | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑18 | | | | | X | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑19 | | | | | X | | | | | | | | | | | | | | | | | | | | | | | | | | X |
|
||||
| PREVENT‑20 | | | | | X | X | X | X | X | X | | | | X | X | | X | X | X | X | X | | X | X | X | X | X | X | X | X | |
|
||||
| PREVENT‑21 | X | | | | | | | | | | | X | | | | | | | | | | | | | | | | | | | |
|
||||
| PREVENT‑22 | | | | | X | | | | | | | | | | | | | | | | | | | | | | | | | | |
|
||||
|
||||
<br>
|
||||
<br>
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
,CRED‑1,CRED‑2,CRED‑3,CRED‑4,CRED‑5,CRED‑6,CRED‑7,CRED‑8,ELEVATE‑1,ELEVATE‑2,ELEVATE‑3,ELEVATE‑4,ELEVATE‑5,EXEC‑1,EXEC‑2,RECON‑1,RECON‑2,RECON‑3,RECON‑4,RECON‑5,RECON‑6,RECON‑7,TAKEOVER‑1,TAKEOVER‑2,TAKEOVER‑3,TAKEOVER‑4,TAKEOVER‑5,TAKEOVER‑6,TAKEOVER‑7,TAKEOVER‑8,TAKEOVER‑9
|
||||
CANARY‑1,X,X,X,X,X,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
DETECT‑1,,,,,,,,X,X,X,X,,,,,,,,,,,,X,X,X,X,X,X,X,X,
|
||||
DETECT‑2,,,,,,,,,,,,,,,,X,,,,,,,,,,,,,,,
|
||||
DETECT‑3,,,,,,,,,X,X,X,,,,,,,,,,,,,,,,,,,,
|
||||
DETECT‑4,,,,,,,,,,,,,,X,,,,,,,,,,,,,,,,,
|
||||
DETECT‑5,,,,,,,,,,,,,,,,,,,X,X,,,X,X,,X,X,X,X,,
|
||||
DETECT‑6,,,,,,,,,,,,,,,,,,,X,X,X,X,X,X,,X,X,X,X,,
|
||||
DETECT‑7,X,,,,,,,,,,,X,X,,,X,,,,,,,,,,,,,,,
|
||||
DETECT‑8,X,,,,,,,,,,,,,,,,,,,,X,,,,,,,,,,
|
||||
DETECT‑9,,,,,,,,,,,,,,,,,,,,,,X,,,,,,,,,
|
||||
PREVENT‑1,,,,,,,,,,X,X,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑2,,,,,,,,,,X,X,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑3,X,X,X,X,X,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑4,,X,X,X,,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑5,,,,,,,,,,X,X,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑6,X,,,,,,,,,,,X,X,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑7,X,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑8,,X,,,,,,,,X,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑9,,,,,,,,,,,,,,X,X,,,,X,X,,X,,,,,X,,,,
|
||||
PREVENT‑10,X,X,X,X,X,X,X,X,,,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑11,,,,,,,,,,X,,,,,,,,,,,,,,,X,,,,,X,
|
||||
PREVENT‑12,,,,,,,,,X,X,X,,,,,,,,,,,,,X,,X,,X,X,,
|
||||
PREVENT‑13,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,X,
|
||||
PREVENT‑14,,,,,,,,X,,,,,,,,,,,,,,,X,,X,,,,,,
|
||||
PREVENT‑15,,,,X,,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑16,,X,,,,,,,,,,,,,,,,,,,,,,,,,,,,X,
|
||||
PREVENT‑17,X,X,X,X,X,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑18,,,,,X,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑19,,,,,X,,,,,,,,,,,,,,,,,,,,,,,,,,X
|
||||
PREVENT‑20,,,,,X,X,X,X,X,X,,,,X,X,,X,X,X,X,X,,X,X,X,X,X,X,X,X,
|
||||
PREVENT‑21,X,,,,,,,,,,,X,,,,,,,,,,,,,,,,,,,
|
||||
PREVENT‑22,,,,,X,,,,,,,,,,,,,,,,,,,,,,,,,,
|
||||
|
@@ -46,10 +46,14 @@ Attackers may recover domain credentials from this process, the difficulty of wh
|
||||
With these credentials, attackers may transition from an unauthenticated context on the network to a domain-authenticated context. If any of the credentials recovered are privileged, it may also enable privilege escalation and lateral movement vectors.
|
||||
|
||||
## Defensive IDs
|
||||
- [CANARY-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/CANARY/CANARY-1/canary-1_description.md)
|
||||
- [DETECT-7: Monitor read access to the SMSTemp directory](../../../defense-techniques/DETECT/DETECT-7/detect-7_description.md)
|
||||
- [DETECT-8: Monitor connections to winreg named pipe](../../../defense-techniques/DETECT/DETECT-8/detect-8_description.md)
|
||||
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
|
||||
- [PREVENT-6: Configure a strong PXE boot password](../../../defense-techniques/PREVENT/PREVENT-6/prevent-6_description.md)
|
||||
- [PREVENT-7: Disable command support in PXE boot configuration](../../../defense-techniques/PREVENT/PREVENT-7/prevent-7_description.md)
|
||||
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
|
||||
- [PREVENT-17: Remove unnecessary privileges from accounts](../../../defense-techniques/PREVENT/PREVENT-17/prevent-17_description.md)
|
||||
- [PREVENT-21: Restrict PXE boot to authorized VLANs](../../../defense-techniques/PREVENT/PREVENT-21/prevent-21_description.md)
|
||||
|
||||
|
||||
|
||||
@@ -41,11 +41,13 @@ In environments using Active Directory defaults, SCCM defaults, and NAAs (or col
|
||||
If the NAA or credential stored in a collection variable or task sequence is implemented under the principle of least privilege, this may not extend the attacker's privilege level in the domain. The more common result: If the NAA is overprivileged, this technique serves as a trivial privilege escalation vector.
|
||||
|
||||
## Defensive IDs
|
||||
- [CANARY-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/CANARY/CANARY-1/canary-1_description.md)
|
||||
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
|
||||
- [PREVENT-4: Configure Enhanced HTTP](../../../defense-techniques/PREVENT/PREVENT-4/prevent-4_description.md)
|
||||
- [PREVENT-8: Require PKI certificates for client authentation](../../../defense-techniques/PREVENT/PREVENT-8/prevent-8_description.md)
|
||||
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
|
||||
- [PREVENT-16: Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts](../../../defense-techniques/PREVENT/PREVENT-16/prevent-16_description.md)
|
||||
- [PREVENT-17: Remove unnecessary privileges from accounts](../../../defense-techniques/PREVENT/PREVENT-17/prevent-17_description.md)
|
||||
|
||||
## Examples
|
||||
Using Powermad and SharpSCCM:
|
||||
|
||||
@@ -27,9 +27,11 @@ This technique may allow an attacker to retrieve plaintext domain credentials. E
|
||||
At SpecterOps, we commonly see accounts that are members of the SCCM `Full Administrator` role and the `Domain Admins` group configured as NAAs.
|
||||
|
||||
## Defensive IDs
|
||||
- [CANARY-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/CANARY/CANARY-1/canary-1_description.md)
|
||||
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
|
||||
- [PREVENT-4: Configure Enhanced HTTP](../../../defense-techniques/PREVENT/PREVENT-4/prevent-4_description.md)
|
||||
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
|
||||
- [PREVENT-17: Remove unnecessary privileges from accounts](../../../defense-techniques/PREVENT/PREVENT-17/prevent-17_description.md)
|
||||
|
||||
## Examples
|
||||
|
||||
|
||||
@@ -29,10 +29,12 @@ At SpecterOps, we commonly see accounts that are members of the SCCM `Full Admin
|
||||
Currently-configured and/or legacy NAA, collection variable, and task sequence configurations may be present in the CIM repository file. If so, an attacker can recover legacy accounts that have been configured in the past. For example, if a system administrator configured their SCCM admin account as the NAA when the site was created, but years later fixed their mistake and no longer use an overprivileged NAA or NAA at all, their SCCM admin credentials may still be on disk on SCCM clients.
|
||||
|
||||
## Defensive IDs
|
||||
- [CANARY-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/CANARY/CANARY-1/canary-1_description.md)
|
||||
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
|
||||
- [PREVENT-4: Configure Enhanced HTTP](../../../defense-techniques/PREVENT/PREVENT-4/prevent-4_description.md)
|
||||
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
|
||||
- [PREVENT-15: Disable legacy network access accounts in Active Directory](../../../defense-techniques/PREVENT/PREVENT-15/prevent-15_description.md)
|
||||
- [PREVENT-17: Remove unnecessary privileges from accounts](../../../defense-techniques/PREVENT/PREVENT-17/prevent-17_description.md)
|
||||
|
||||
## Examples
|
||||
|
||||
|
||||
@@ -22,10 +22,14 @@ From the site server, which is granted the `sysadmin` role on the site database,
|
||||
If an attacker can compromise the primary site server, they can recover plaintext credentials for any account stored in the site database.
|
||||
|
||||
## Defensive IDs
|
||||
- [CANARY-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/CANARY/CANARY-1/canary-1_description.md)
|
||||
- [PREVENT-3: Harden or disable network access accounts](../../../defense-techniques/PREVENT/PREVENT-3/prevent-3_description.md)
|
||||
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
|
||||
- [PREVENT-17: Remove unnecessary privileges from accounts](../../../defense-techniques/PREVENT/PREVENT-17/prevent-17_description.md)
|
||||
- [PREVENT-18: Use strong passwords for DBA accounts](../../../defense-techniques/PREVENT/PREVENT-18/prevent-18_description.md)
|
||||
- [PREVENT-19: Remove unnecessary links to site databases](../../../defense-techniques/PREVENT/PREVENT-19/prevent-19_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
- [PREVENT-22: Do not manage assets in two or more segmented forests, domains, networks, or security tiers](../../../defense-techniques/PREVENT/PREVENT-22/prevent-22_description.md)
|
||||
|
||||
## Examples
|
||||
|
||||
|
||||
@@ -37,7 +37,6 @@ If anonymous authentication (no credentials required) is enabled, an attacker ca
|
||||
If authentication is required: An internal attacker can use existing credentials to authenticate to the SMB/HTTP services to loot the Distribution Points.
|
||||
|
||||
## Defensive IDs
|
||||
|
||||
- [PREVENT-10: Enforce the principle of least privilege for accounts](../../../defense-techniques/PREVENT/PREVENT-10/prevent-10_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -40,6 +40,7 @@ Impact for these scenarios is difficult to quantify. In some cases a compromised
|
||||
|
||||
## Defensive IDs
|
||||
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
|
||||
- [DETECT-3: Monitor client push installation accounts authenticating from anywhere other than the primary site server](../../../defense-techniques/DETECT/DETECT-3/detect-3_description.md)
|
||||
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -51,6 +51,7 @@ If all configured accounts fail when the site server tries to authenticate to a
|
||||
- [PREVENT-8: Require PKI certificates for client authentication](../../../defense-techniques/PREVENT/PREVENT-8/prevent-8_description.md)
|
||||
- [PREVENT-11: Disable and uninstall WebClient on site servers](../../../defense-techniques/PREVENT/PREVENT-11/prevent-11_description.md)
|
||||
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
## Examples
|
||||
It is not possible to identify whether automatic site-wide client push installation, automatic site assignment, and `Allow connection fallback to NTLM` are enabled without attempting this attack.
|
||||
|
||||
@@ -106,6 +106,7 @@ mSSMSSiteCode: ACT
|
||||
|
||||
## Defensive IDs
|
||||
- [DETECT-2: Monitor read access to the `System Management` Active Directory container](../../../defense-techniques/DETECT/DETECT-2/detect-2_description.md)
|
||||
- [DETECT-7: Monitor read access to the SMSTemp directory](../../../defense-techniques/DETECT/DETECT-7/detect-7_description.md)
|
||||
|
||||
## Examples
|
||||
|
||||
|
||||
@@ -54,6 +54,8 @@ These operations allow for enumeration of:
|
||||
And a lot more. There are more than 130 queries available.
|
||||
|
||||
## Defensive IDs
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-9: Enforce MFA for SMS provider calls](../../../defense-techniques/PREVENT/PREVENT-9/prevent-9_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -27,6 +27,8 @@ Attributes that clients periodically report to their management point can be que
|
||||
Attackers can assume that these users either have an active session or may log onto these systems again, in which case stored credentials in memory could be used to conduct further actions in the context of that user. For example, they could identify devices where a member of the `Domain Admins` group is the primary user or the last to log on and move laterally to the system or coerce NTLM authentication to compromise their account (EXEC-1).
|
||||
|
||||
## Defensive IDs
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-9: Enforce MFA for SMS provider calls](../../../defense-techniques/PREVENT/PREVENT-9/prevent-9_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -38,6 +38,7 @@ Additionally, the registry key/value of `HKLM:\SOFTWARE\Microsoft\SMS\DP\Managem
|
||||
5. A resolved MP site system role can be used to elevate privileges via credential relay attacks [ELEVATE-1](../../ELEVATE/ELEVATE-1/ELEVATE-1_description.md)
|
||||
|
||||
## Defensive IDs
|
||||
- [DETECT-7: Monitor local object access for SCCM logs and settings](../../../defense-techniques/DETECT/DETECT-7/detect-7_description.md)
|
||||
- [DETECT-9: Monitor local object access for local SCCM logs and settings](../../../defense-techniques/DETECT/DETECT-9/detect-9_description.md)
|
||||
|
||||
## Examples
|
||||
|
||||
@@ -39,6 +39,8 @@ The "Full Administrator" security role is granted all permissions in Configurati
|
||||
|
||||
## Defensive IDs
|
||||
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-14: Require EPA on AD CS and site databases](../../../defense-techniques/PREVENT/PREVENT-14/prevent-14_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -41,6 +41,8 @@ The "Full Administrator" security role is granted all permissions in Configurati
|
||||
|
||||
## Defensive IDs
|
||||
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -50,7 +50,7 @@ The "Full Administrator" security role is granted all permissions in Configurati
|
||||
## Defensive IDs
|
||||
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -38,7 +38,7 @@ This technique may allow an attacker to relay a site server's domain computer ac
|
||||
## Defensive IDs
|
||||
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-9: Enforce MFA for SMS Provider calls](../../../defense-techniques/PREVENT/PREVENT-9/prevent-9_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -41,7 +41,7 @@ This technique may allow an attacker to relay a site server domain computer acco
|
||||
## Defensive IDs
|
||||
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -45,7 +45,7 @@ The "Full Administrator" security role is granted all permissions in Configurati
|
||||
## Defensive IDs
|
||||
- [DETECT-1: Monitor site server domain computer accounts authenticating from another source](../../../defense-techniques/DETECT/DETECT-1/detect-1_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for SMS Admins](../../../defense-techniques/DETECT/DETECT-5/detect-5_description.md)
|
||||
- [DETECT-5: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [DETECT-6: Monitor group membership changes for RBAC_Admins table](../../../defense-techniques/DETECT/DETECT-6/detect-6_description.md)
|
||||
- [PREVENT-12: Require SMB signing on site systems](../../../defense-techniques/PREVENT/PREVENT-12/prevent-12_description.md)
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
|
||||
@@ -67,7 +67,7 @@ The example below displays a successful logon event for the SCCM site server fro
|
||||
- [TAKEOVER-1: NTLM coercion and relay to MSSQL on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-1/takeover-1_description.md)
|
||||
- [TAKEOVER-2: NTLM coercion and relay to SMB on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-2/takeover-2_description.md)
|
||||
- [TAKEOVER-3: NTLM coercion and relay to HTTP on AD CS](../../../attack-techniques/TAKEOVER/TAKEOVER-3/)
|
||||
- [TAKEOVER-4: NTLM coercion and relay from CAS to origin primary site server](../../../attack-techniques/TAKEOVER/TAKEOVER-5/takeover-5_description.md)
|
||||
- [TAKEOVER-4: NTLM coercion and relay from CAS to origin primary site server](../../../attack-techniques/TAKEOVER/TAKEOVER-4/takeover-4_description.md)
|
||||
- [TAKEOVER-5: NTLM coercion and relay to AdminService on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-5/takeover-5_description.md)
|
||||
- [TAKEOVER-6: NTLM coercion and relay to SMB on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md)
|
||||
- [TAKEOVER-7: NTLM coercion and relay to SMB between primary and passive site servers](../../../attack-techniques/TAKEOVER/TAKEOVER-7/takeover-7_description.md)
|
||||
|
||||
@@ -107,6 +107,10 @@ Process Information:
|
||||
## Associated Offensive IDs
|
||||
- [TAKEOVER-1: Hierarchy takeover via NTLM coercion and relay to MSSQL on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-1/takeover-1_description.md)
|
||||
- [TAKEOVER-2: Hierarchy takeover via NTLM coercion and relay to SMB on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-2/takeover-2_description.md)
|
||||
- [TAKEOVER-4: NTLM coercion and relay from CAS to origin primary site server](../../../attack-techniques/TAKEOVER/TAKEOVER-4/takeover-4_description.md)
|
||||
- [TAKEOVER-5: NTLM coercion and relay to AdminService on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-5/takeover-5_description.md)
|
||||
- [TAKEOVER-6: NTLM coercion and relay to SMB on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md)
|
||||
- [TAKEOVER-7: NTLM coercion and relay to SMB between primary and passive site servers](../../../attack-techniques/TAKEOVER/TAKEOVER-7/takeover-7_description.md)
|
||||
- [RECON-4: Query client devices via CMPivot](../../../attack-techniques/RECON/RECON-4/recon-4_description.md)
|
||||
- [RECON-5: Locate users via SMS Provider](../../../attack-techniques/RECON/RECON-5/recon-5_description.md)
|
||||
|
||||
|
||||
@@ -91,6 +91,10 @@ host_name:UVJyJtIi
|
||||
## Associated Offensive IDs
|
||||
- [TAKEOVER-1: Hierarchy takeover via NTLM coercion and relay to MSSQL on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-1/takeover-1_description.md)
|
||||
- [TAKEOVER-2: Hierarchy takeover via NTLM coercion and relay to SMB on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-2/takeover-2_description.md)
|
||||
- [TAKEOVER-4: NTLM coercion and relay from CAS to origin primary site server](../../../attack-techniques/TAKEOVER/TAKEOVER-4/takeover-4_description.md)
|
||||
- [TAKEOVER-5: NTLM coercion and relay to AdminService on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-5/takeover-5_description.md)
|
||||
- [TAKEOVER-6: NTLM coercion and relay to SMB on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-6/takeover-6_description.md)
|
||||
- [TAKEOVER-7: NTLM coercion and relay to SMB between primary and passive site servers](../../../attack-techniques/TAKEOVER/TAKEOVER-7/takeover-7_description.md)
|
||||
- [RECON-4: Query client devices via CMPivot](../../../attack-techniques/RECON/RECON-4/recon-4_description.md)
|
||||
- [RECON-5: Locate users via SMS Provider](../../../attack-techniques/RECON/RECON-5/recon-5_description.md)
|
||||
|
||||
|
||||
@@ -116,6 +116,8 @@ Access Request Information:
|
||||
## Associated Offensive IDs
|
||||
- [RECON-1: Enumerate SCCM site information via LDAP](../../../attack-techniques/RECON/RECON-1/recon-1_description.md)
|
||||
- [CRED-1: Retrieve secrets from PXE boot media](../../../attack-techniques/CRED/CRED-1/cred-1_description.md)
|
||||
- [ELEVATE-4: Distribution Point Takeover via PXE Boot Spoofing](../../../attack-techniques/ELEVATE/ELEVATE-4/ELEVATE-4_description.md)
|
||||
- [ELEVATE-5: Distribution Point Takeover via OSD Media Recovery](../../../attack-techniques/ELEVATE/ELEVATE-5/ELEVATE-5_description.md)
|
||||
|
||||
## References
|
||||
- Garrett Foster, [SCCMHunter Find Module](https://github.com/garrettfoster13/sccmhunter/wiki/find)
|
||||
|
||||
@@ -131,6 +131,8 @@ Nothing specifically requires that these variables be credentials, but they can
|
||||
- [CRED-3: Dump currently deployed credentials via WMI](../../../attack-techniques/CRED/CRED-3/cred-3_description.md)
|
||||
- [CRED-4: Retrieve legacy network access account (NAA) credentials from the CIM Repository](../../../attack-techniques/CRED/CRED-4/cred-4_description.md)
|
||||
- [CRED-5: Dump SCCM credentials from site database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
|
||||
- [CRED-6: Loot domain credentials, SSH keys, and more from SCCM Distribution Points (DP)](../../../attack-techniques/CRED/CRED-6/cred-6_description.md)
|
||||
- [CRED-7: Retrieve credentials via AdminService API](../../../attack-techniques/CRED/CRED-7/cred-7_description.md)
|
||||
- [CRED-8: NTLM relay remote MP to site database to extract machine policy secrets](../../../attack-techniques/CRED/CRED-8/cred-8_description.md)
|
||||
|
||||
## References
|
||||
|
||||
@@ -14,6 +14,7 @@ This service is installed by default on workstation versions of Windows and can
|
||||
- [PREVENT-20: Block unnecessary connections to site systems](../../../defense-techniques/PREVENT/PREVENT-20/prevent-20_description.md)
|
||||
|
||||
## Associated Offensive IDs
|
||||
- [ELEVATE-2: NTLM relay via automatic client push installation](../../../attack-techniques/ELEVATE/ELEVATE-2/ELEVATE-2_description.md)
|
||||
- [TAKEOVER-3: NTLM coercion and relay to HTTP on AD CS](../../../attack-techniques/TAKEOVER/TAKEOVER-3/takeover-3_description.md)
|
||||
- [TAKEOVER-8: NTLM relay primary site server HTTP to LDAP on domain controller](../../../attack-techniques/TAKEOVER/TAKEOVER-8/takeover-8_description.md)
|
||||
|
||||
|
||||
@@ -7,11 +7,10 @@ Use strong passwords for DBA accounts
|
||||
This is the bulk of the content
|
||||
|
||||
## Linked Defensive IDs
|
||||
- Remove if not relevant
|
||||
|
||||
|
||||
## Associated Offensive IDs
|
||||
|
||||
[CRED-5: Dump credentials from the site database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
|
||||
|
||||
## References
|
||||
Author, Title, Link
|
||||
@@ -9,9 +9,9 @@ Configuration Manager installations with multiple sites in a hierarchy will crea
|
||||
It is crucial to ensure the links to other SCCM site database servers are not removed, as this will break functionality. Therefore, ensure proper due diligence for the target servers and databases before removing links.
|
||||
|
||||
## Linked Defensive IDs
|
||||
- [CRED-5: Dump credentials from the site database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
|
||||
|
||||
## Associated Offensive IDs
|
||||
- [CRED-5: Dump credentials from the site database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
|
||||
- [TAKEOVER-9: Crawl site database links configured with DBA privileges](../../../attack-techniques/TAKEOVER/TAKEOVER-9/takeover-9_description.md)
|
||||
|
||||
## References
|
||||
|
||||
@@ -18,6 +18,9 @@ To help prevent NTLM coercion and relay and remote management from untrusted, no
|
||||
|
||||
## Associated Offensive IDs
|
||||
- [CRED-5: Dump credentials from the site database](../../../attack-techniques/CRED/CRED-5/cred-5_description.md)
|
||||
- [CRED-6: Loot domain credentials, SSH keys, and more from SCCM Distribution Points (DP)](../../../attack-techniques/CRED/CRED-6/cred-6_description.md)
|
||||
- [CRED-7: Retrieve credentials via AdminService API](../../../attack-techniques/CRED/CRED-7/cred-7_description.md)
|
||||
- [CRED-8: Extract credentials from SCCM policies by coercing and relaying management point (MP) NTLM authentication to the site database](../../../attack-techniques/CRED/CRED-8/cred-8_description.md)
|
||||
- [ELEVATE-1: NTLM relay site server to SMB on site systems](../../../attack-techniques/ELEVATE/ELEVATE-1/ELEVATE-1_description.md)
|
||||
- [ELEVATE-2: NTLM relay via automatic client push installation](../../../attack-techniques/ELEVATE/ELEVATE-2/ELEVATE-2_description.md)
|
||||
- [EXEC-1: Application deployment](../../../attack-techniques/EXEC/EXEC-1/exec-1_description.md)
|
||||
@@ -26,6 +29,7 @@ To help prevent NTLM coercion and relay and remote management from untrusted, no
|
||||
- [RECON-3: Enumerate SCCM roles via HTTP](../../../attack-techniques/RECON/RECON-3/recon-3_description.md)
|
||||
- [RECON-4: Query client devices via CMPivot](../../../attack-techniques/RECON/RECON-4/recon-4_description.md)
|
||||
- [RECON-5: Locate users via SMS Provider](../../../attack-techniques/RECON/RECON-5/RECON-5_description.md)
|
||||
- [RECON-6: Enumerate SCCM roles via the SMB Named Pipe winreg](../../../attack-techniques/RECON/RECON-6/recon-6_description.md)
|
||||
- [TAKEOVER-1: NTLM coercion and relay to MSSQL on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-1/takeover-1_description.md)
|
||||
- [TAKEOVER-2: NTLM coercion and relay to SMB on remote site database](../../../attack-techniques/TAKEOVER/TAKEOVER-2/takeover-2_description.md)
|
||||
- [TAKEOVER-3: NTLM coercion and relay to HTTP on AD CS](../../../attack-techniques/TAKEOVER/TAKEOVER-3/)
|
||||
|
||||
@@ -19,6 +19,7 @@ There is another method: DHCP options. Microsoft [does not recommend](https://te
|
||||
|
||||
## Associated Offensive IDs
|
||||
- [CRED-1: Retrieve secrets from PXE boot media](../../../attack-techniques/CRED/CRED-1/cred-1_description.md)
|
||||
- [ELEVATE-4: Distribution Point Takeover via PXE Boot Spoofing](../../../attack-techniques/ELEVATE/ELEVATE-4/ELEVATE-4_description.md)
|
||||
|
||||
## References
|
||||
- Microsoft, [Boot From PXE Server](https://learn.microsoft.com/en-us/troubleshoot/mem/configmgr/os-deployment/boot-from-pxe-server)
|
||||
|
||||
@@ -17,6 +17,8 @@ _Figure 1 - Enhanced HTTP Diagram_
|
||||
|
||||
## Associated Offensive IDs
|
||||
- [CRED-2: Request machine policy and deobfuscate secrets](../../../attack-techniques/CRED/CRED-2/cred-2_description.md)
|
||||
- [CRED-3: Dump currently deployed secrets via WMI](../../../attack-techniques/CRED/CRED-3/cred-3_description.md)
|
||||
- [CRED-4: Retrieve legacy secrets from the CIM repository](../../../attack-techniques/CRED/CRED-4/cred-4_description.md)
|
||||
|
||||
## References
|
||||
- Microsoft, Enhanced HTTP, https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/enhanced-http
|
||||
@@ -20,6 +20,8 @@ This password can be retrieve using tools like [PXEThief](https://github.com/MWR
|
||||
|
||||
## Associated Offensive IDs
|
||||
- [CRED-1: Retrieve secrets from PXE boot media](../../../attack-techniques/CRED/CRED-1/cred-1_description.md)
|
||||
- [ELEVATE-4: Distribution Point Takeover via PXE Boot Spoofing](../../../attack-techniques/ELEVATE/ELEVATE-4/ELEVATE-4_description.md)
|
||||
- [ELEVATE-5: Distribution Point Takeover via OSD Media Recovery](../../../attack-techniques/ELEVATE/ELEVATE-5/ELEVATE-5_description.md)
|
||||
|
||||
## References
|
||||
- Microsoft, [Understanding PXE Boot](https://learn.microsoft.com/en-us/troubleshoot/mem/configmgr/os-deployment/understand-pxe-boot)
|
||||
|
||||
@@ -11,7 +11,10 @@ Configure a requirement for multi-factor authentication to access WMI/AdminServi
|
||||
|
||||
## Associated Offensive IDs
|
||||
- [EXEC-1: Application deployment](../../../attack-techniques/EXEC/EXEC-1/exec-1_description.md)
|
||||
- [EXEC-2: PowerShell script execution](../../../attack-techniques/EXEC/EXEC-2/exec-2_description.md)
|
||||
- [RECON-4: Query client devices via CMPivot](../../../attack-techniques/RECON/RECON-4/recon-4_description.md)
|
||||
- [RECON-5: Locate users via SMS Provider](../../../attack-techniques/RECON/RECON-5/recon-5_description.md)
|
||||
- [RECON-7: Enumerate SCCM site information via local files](../../../attack-techniques/RECON/RECON-7/recon-7_description.md)
|
||||
- [TAKEOVER-5: NTLM coercion and relay to AdminService on remote SMS Provider](../../../attack-techniques/TAKEOVER/TAKEOVER-5/takeover-5_description.md)
|
||||
|
||||
## References
|
||||
|
||||
Reference in New Issue
Block a user