Tradecraft-SCCM


#sccm #tradecraft #RedTeaming

TLDR

Setup a SACL/honey trap on the NAA account instead of removing it. It is a perfect trap.

SCCM

Microsoft System Center Configuration Manager (also known as SCCM) is a core component of enterprise IT infrastructure, enabling centralized software and device management of large-scale Windows environments. From an attacker’s lens, any client-server architecture offers significant value once you gain access to the centralized infrastructure. SCCM, however, can still provide meaningful opportunities even from systems that are not SCCM-managed clients.

Attack Surface

Initial Domain Access (Beacon / Network Foothold) → NAA Discovery → NAA Account Exploration

Tools and Tradecraft

Warning: Relaying is not opsec friendly

Back to top ↑