CRED-2 - Policy Request Credentials

Document Reference

Description

Request computer policy and deobfuscate secrets

Requirements

  • PKI certificates are not required for client authentication

Additionally, any of the below requirements can be met to perform this attack.

  • Domain Computer credentials

  • The ability to create computer objects (MachineAccountQuota)

  • Local administrator on a SCCM client

Windows

Local Administrator on SCCM Client

If you are a local administrator or running as SYSTEM on a SCCM client. We can simply request the computer policy without specifying any credentials

Using Domain Computer Credentials

If we have a password for a domain computer account we can use this directly with SharpSCCM to register a new device

Machine Account Quota

Create new machine account with Powermad

Use SharpSCCM to request policy for the new account

Linux

SCCMhunter

Last updated