sccm-mecm-attack
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation includes numerous command-line examples for running security assessment tools like
sccmhunter,SharpSCCM,ntlmrelayx, andSCCMSecrets. These commands are intended for infrastructure reconnaissance, NTLM relay attacks, and administrative API interaction. - [DATA_EXFILTRATION]: It outlines techniques for harvesting sensitive environment data, specifically targeting Microsoft SCCM components. This includes extracting Network Access Account (NAA) credentials, decrypting PXE boot media passwords, and looting scripts and certificates from Distribution Points using tools like
cmloot. - [CREDENTIALS_UNSAFE]: Detailed procedures are provided for obtaining domain credentials and system secrets through DPAPI extraction, WMI queries, and direct manipulation of the SCCM Site Database (MSSQL). The skill serves as a guide for credential harvesting rather than containing embedded secrets.
Audit Metadata