Product
rumour
rumour
Monitoring Malicious Use of SCCM Application Execution
1 TTPThis brief documents the execution mechanics of Microsoft System Center Configuration Manager (SCCM), identifying risks where adversary-controlled software or scripts are deployed through the SCCM client infrastructure.
System Center Configuration Manager
execution
enterprise-management
windows
monitoring
1t
medium
advisory
Potential Windows Session Hijacking via CcmExec
2 rules 1 TTPAdversaries may exploit Microsoft's System Center Configuration Manager by loading malicious DLLs into SCNotification.exe, a process associated with user notifications, potentially leading to Windows session hijacking.
System Center Configuration Manager
defense-evasion
dll-hijacking
sccm
2r
1t