Misconfiguration Manager: Still Overlooked, Still Overprivileged
ID: d3350325-267c-590d-add5-d1110bffc798
STIX ID: report--d3350325-267c-590d-add5-d1110bffc798
Feed Name: SpecterOps Blog
A year after launch, Misconfiguration Manager reports substantial community-driven progress in documenting SCCM adversary tradecraft, adding new reconnaissance, credential access, privilege escalation, execution, and coercion techniques (e.g., RECON-6/7, CRED-6/7/8, ELEVATE-4/5, EXEC-3, COERCE-1/2) and detections (DETECT-5–9), plus updated tooling. The post highlights measurable impact (more SCCM reports to MSRC, Microsoft UI/security enhancements), credits key contributors and tools, and previews in-progress items (e.g., TAKEOVER-10, task sequence/baseline execution).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
