sccm-mecm-attack

Fail

Audited by Socket on Jun 16, 2026

4 alerts found:

Malwarex4
MalwareHIGH
references/site-takeover.md

The provided content is a highly malicious SCCM/ConfigMgr intrusion playbook. It instructs coercion/NTLM-relay abuse to gain persistent “Full Administrator” privileges by directly manipulating SCCM RBAC storage (SQL INSERTs into RBAC tables) and/or by invoking AdminService SMS_Admin operations, followed by SCCM-driven remote payload deployment and lateral movement. While this is not “package/library code” in the traditional sense, any software component that embeds or automates these behaviors would represent an extreme supply-chain security risk.

Confidence: 60%Severity: 90%
MalwareHIGH
references/credential-harvesting.md

This fragment is highly indicative of malicious/weaponized intent: it provides actionable steps to compromise SCCM/ConfigMgr, retrieve “secret policies,” decrypt protected NAA/task-sequence/collection-variable secrets, and harvest sensitive deployment artifacts from distribution points. It documents network abuse (device registration/secret-policy requests), NTLM relay to obtain secrets, and local DPAPI/WMI extraction paths—ultimately yielding plaintext credential material. If distributed within a software package (even as documentation or scripts), it should be treated as a credential-stealing capability rather than benign code.

Confidence: 60%Severity: 90%
MalwareHIGH
references/sccm-enumeration.md

This content is highly aligned with malicious reconnaissance and potential credential/material extraction against enterprise SCCM/ConfigMgr environments. While it is presented as operational instructions rather than a library dependency code snippet, the actions described (authenticated LDAP/WMI queries, SCCM policy retrieval, and explicit PXE decryption) indicate meaningful misuse potential. Treat as high-risk abusive guidance if found in or distributed with a software package.

Confidence: 60%Severity: 90%
MalwareHIGH
SKILL.md

MALICIOUS。该技能的实际用途就是让 AI 代理执行 SCCM/MECM 攻击链:窃取凭证、relay 认证、写入管理员、远程投递 payload 并横向移动。供应链上还依赖多个外部安全工具并向其转发高价值凭证,进一步放大风险。

Confidence: 60%Severity: 90%
Audit Metadata
Analyzed At
Jun 16, 2026, 03:14 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fsccm-mecm-attack%2F@28199866b33c65060a90ef44ffb6d69f45feb2eee42b87d65335a4e7d8f9f3fb
Security Audit — socket — sccm-mecm-attack