logo

Misconfiguration Manager: Still Overlooked, Still Overprivileged

ID: d3350325-267c-590d-add5-d1110bffc798

STIX ID: report--d3350325-267c-590d-add5-d1110bffc798

Feed Name: SpecterOps Blog

Date Published: 2025-06-26

Date Updated: 2026-04-30

Author: Duane Michael; Garrett Foster

...
...

A year after launch, Misconfiguration Manager reports substantial community-driven progress in documenting SCCM adversary tradecraft, adding new reconnaissance, credential access, privilege escalation, execution, and coercion techniques (e.g., RECON-6/7, CRED-6/7/8, ELEVATE-4/5, EXEC-3, COERCE-1/2) and detections (DETECT-5–9), plus updated tooling. The post highlights measurable impact (more SCCM reports to MSRC, Microsoft UI/security enhancements), credits key contributors and tools, and previews in-progress items (e.g., TAKEOVER-10, task sequence/baseline execution).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.