Files

Codename Matrix Shortname Description Security Context Network Access
CRED1 PXE Credentials Retrieve secrets from PXE boot media Unauthenticated Internal network
CRED2 Policy Request Credentials Request machine policy and deobfuscate secrets Domain computer creds Internal network
CRED3 DPAPI Credentials Dump currently deployed secrets via WMI Client device admin Any
CRED4 Legacy Credentials Retrieve legacy secrets from the CIM repository Client device admin Any
CRED5 Site Database Credentials Retrieve credentials from the site database Primary site server admin, site database read Internal network
CRED6 Looting Distribution Points Loot Distribution Points via SMB or SCCM Domain User or Unauthenticated (at times) Any
CRED7 AdminService API Credentials Retrieve credentials via AdminService API SCCM administrator Internal network
CRED8 Policy Creds MP Relay NTLM relay remote MP to site database to extract machine policy secrets Domain user creds Internal network
ELEVATE1 Relay to Site System (SMB) NTLM relay site server to SMB on site systems Domain user creds Internal network
ELEVATE2 Relay Client Push Installation NTLM relay via automatic client push installation Domain user creds Internal network
ELEVATE3 Relay Client Push Installation NTLM relay via automatic client push installation and AD System Discovery Domain user creds Internal network
ELEVATE4 PXE PKI Credentials Distribution Point Takeover via PXE Boot Spoofing Unauthenticated Internal network
ELEVATE5 OSD PKI Credentials Distribution Point Takeover via OSD Media Recovery Domain user creds Internal network
ELEVATE6 LPE via Writable Client Cache LPE via Writable Client Cache (ccmcache) Package Replacement Local Privilege Escelation (SYSTEM) Internal network
EXEC1 App Deployment Application deployment SCCM administrator Internal network
EXEC2 Script Deployment PowerShell script execution SCCM administrator Internal network
RECON1 LDAP Enumeration Enumerate SCCM site information via LDAP Authenticated domain user Internal network
RECON2 SMB Enumeration Enumerate SCCM roles via SMB Authenticated domain user Internal network
RECON3 HTTP Enumeration Enumerate SCCM roles via HTTP Authenticated domain user Internal network
RECON4 CMPivot Query client devices via CMPivot SCCM administrator Internal network
RECON5 SMS Provider Enumeration Locate users via SMS Provider SCCM administrator Internal network
RECON6 Remote Registry Enumeration SCCM Site System Role Enumeration via Remote Registry Authenticated domain user Internal network
RECON7 Local File Site Numeration SCCM Site Enumeration via Local Files on Clients Local admin on SCCM client Internal network
TAKEOVER1 Relay to Site DB (MSSQL) NTLM coercion and relay to MSSQL on remote site database Domain user creds Internal network
TAKEOVER2 Relay to Site DB (SMB) NTLM coercion and relay to SMB on remote site database Domain user creds Internal network
TAKEOVER3 Relay to AD CS NTLM coercion and relay to HTTP on AD CS Domain user creds Internal network
TAKEOVER4 Relay CAS to Child NTLM coercion and relay from CAS to origin primary site server Domain user creds Internal network
TAKEOVER5 Relay to AdminService NTLM coercion and relay to AdminService on remote SMS Provider Domain user creds Internal network
TAKEOVER6 Relay to SMS Provider (SMB) NTLM coercion and relay to SMB on remote SMS Provider Domain user creds Internal network
TAKEOVER7 Relay Between HA NTLM coercion and relay to SMB between primary and passive site servers Domain user creds Internal network
TAKEOVER8 Relay to LDAP NTLM coercion and relay HTTP to LDAP on domain controller Domain user creds Internal network
TAKEOVER9 SQL Linked as DBA Crawl site database links configured with DBA privileges Authenticated database user Internal network
COERCE1 CMPivot coercion NTLM coercion via CMPivot query CMPivot administrator Internal network
COERCE2 CcmExec Coercion NTLM coercion via SCNotification AppDomainManager Injection Local admin on SCCM client Internal network