Why isnt SCCM a more common target?

maybe i am just not like, inthe loop but i feel like SCCM would be an obvious goal? if i can get to a point i could propegate something through the whole environment, why wouldnt i target it? granted i dont pay the most attention, so maybe i am just missing the discourse (said the thing) about it? maybe it is, but i just dont see a whole lot of discourse (said the thing) on it. just feels like itd be more of a common point of discussion. this question is totally not for filling up the forum so it doesnt look empty when it starts being advertised! :smiley:

1 Like

Im pretty sure it is a common target if its not difficult? or am i wrong?

Yeah, it is. At least when there isnt easier options first. Path of least resistence and all that.

Also, it isn’t always trivial, and abusing SCCM can be extremely loud, and disruptive.

is it just easier to spray creds?

(post deleted by author) is so gay.

typically yeah, also remember that most hacks are goal focused, if you are a β€œblackhat” group (ransomware, CNO, extortion) its typically more trouble than its worth

if you wanna see if you can just do it sure, go crazy

id also expect for most red teaming/pentesting stuff, its out of scope to push to a whole environment during operational hours

β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œblackhatβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€β€œβ€