logo

Attacking System Center Operations Manager (Part 1)

ID: 76f6b0b8-c831-5dfb-bd4a-56bd254c5d4c

STIX ID: report--76f6b0b8-c831-5dfb-bd4a-56bd254c5d4c

Feed Name: SpecterOps Blog

Threat Score
70/100

Date Published: 2025-12-10

Date Updated: 2026-04-30

Author: Garrett Foster

...
...

This research blog analyzes insecure default configurations and practical attack paths in Microsoft System Center Operations Manager (SCOM), demonstrating how an attacker can enumerate AD-integrated SCOM deployments, abuse service accounts and SPNs, recover RunAs credentials, execute code via the web management console (PowerShell widget and NTLM relaying), and ultimately take over management groups and monitored clients; it includes detection guidance and hardening recommendations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.