Published inPosts By SpecterOps Team MembersMaestroAbusing Intune for Lateral Movement Over C2Oct 31, 2024Oct 31, 2024
Published inPosts By SpecterOps Team MembersRooting out Risky SCCM Configs with Misconfiguration Managertl;dr: I wrote a script to identify every TAKEOVER and ELEVATE attack in Misconfiguration Manager.Apr 11, 2024Apr 11, 2024
Published inPosts By SpecterOps Team MembersSCCM Hierarchy TakeoverOne Site to Rule Them AllSep 25, 20231Sep 25, 20231
Published inPosts By SpecterOps Team MembersSCCM Site Takeover via Automatic Client Push Installationtl;dr: Install hotfix KB15599094 and disable NTLM for client push installation.Jan 12, 2023Jan 12, 2023
Published inPosts By SpecterOps Team MembersRelaying NTLM Authentication from SCCM Clientstl;dr: Seriously, please disable NTLMJun 30, 2022Jun 30, 2022
Published inPosts By SpecterOps Team MembersCoercing NTLM Authentication from SCCMtl;dr: Disable NTLM for Client Push InstallationApr 13, 20221Apr 13, 20221