logo

I’d Like to Speak to Your Manager: Stealing Secrets with Management Point Relays

ID: f7d825d8-cd5e-5950-8eb9-9f932812fb5b

STIX ID: report--f7d825d8-cd5e-5950-8eb9-9f932812fb5b

Feed Name: SpecterOps Blog

Threat Score
75/100

Date Published: 2025-07-15

Date Updated: 2026-04-30

Author: Garrett Foster

...
...

This research post demonstrates an SCCM/MECM attack path where an adversary can coerce a Management Point to relay authentication to the site SQL database (via NTLM relay and PetitPotam), call procedures such as MP_GetMachinePolicyAssignments and MP_GetPolicyBody, and recover/decrypt sensitive policies including Network Access Account credentials and Task Sequence variables; the author supplies PoC commands (ntlmrelayx, PetitPotam, mssqlclient.py, PXEthief), implementation analysis, and defensive guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.