Attacking System Center Operations Manager (Part 1)
ID: 76f6b0b8-c831-5dfb-bd4a-56bd254c5d4c
STIX ID: report--76f6b0b8-c831-5dfb-bd4a-56bd254c5d4c
Feed Name: SpecterOps Blog
This research blog analyzes insecure default configurations and practical attack paths in Microsoft System Center Operations Manager (SCOM), demonstrating how an attacker can enumerate AD-integrated SCOM deployments, abuse service accounts and SPNs, recover RunAs credentials, execute code via the web management console (PowerShell widget and NTLM relaying), and ultimately take over management groups and monitored clients; it includes detection guidance and hardening recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
