Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

SCCM - The Tree That Always Bears Bad Fruits

DEFCONConference via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore advanced red team techniques targeting Microsoft Configuration Manager (SCCM) in this 39-minute DEF CON 33 conference talk. Discover why SCCM has become a preferred target for penetration testers and how its complexity and technical debt create persistent security vulnerabilities that organizations struggle to remediate. Learn how compromising an SCCM deployment can lead to full Active Directory takeover with less effort than traditional attack vectors. Gain insights from original security research that uncovered multiple zero-day vulnerabilities, including CVE-2024-43468, an unauthenticated SQL injection flaw. Master reconnaissance techniques for SCCM environments, understand deployment hierarchies, and learn methods for bypassing security boundaries. Examine newly discovered vulnerabilities that enable complete deployment compromise and explore post-exploitation techniques following database access. Get introduced to a battle-tested open-source tool that implements these attack methods, and discover a persistence technique for installing backdoors as legitimate servicing endpoints within SCCM infrastructure.

Syllabus

DEF CON 33 - SCCM: The tree that always bears bad fruits - Mehdi 'kalimer0x00' Elyassa

Taught by

DEFCONConference

Reviews

Start your review of SCCM - The Tree That Always Bears Bad Fruits

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.