logo

Exploring SCCM by Unobfuscating Network Access Accounts

ID: b9883521-6c76-5b09-a574-9361f3f85308

STIX ID: report--b9883521-6c76-5b09-a574-9361f3f85308

Feed Name: XPN Infosec Blog

Threat Score
65/100

Date Published: 2022-07-09

Date Updated: 2026-07-30

...
...

This blog post reverse-engineers SCCM's HTTP API and client registration to show a practical abuse path: an attacker able to create a computer account can register a fake SCCM client, cause it to be Approved, download secret NAAConfig policies encrypted to the client's key, and recover Network Access Account credentials offline by decrypting the PKCS#7 payload and applying the client-side unobfuscation routine; the author provides analysis, debugging notes, and proof-of-concept code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.