THREAT OPS › Threat News › Unmasking SCCM Application Execution
Unmasking SCCM Application Execution
<div class="wp-block-image"> <figure class="aligncenter size-full"><img alt="" class="wp-image-29594" src="https://specterops.io/wp-content/uploads/sites/3/2026/09/Screenshot-2026-09-08-at-3.17.03-PM.png" /></figure> </div>
<p class="wp-block-paragraph"><em><strong>TL;DR: </strong>Executing applications instead of scripts via SCCM’s deploy application feature will generate different artifacts du
MITRE ATT&CK techniques
- PowerShellT1059.001
Indicators of compromise
- https://blog.snapattack.com/a-detection-engineers-guide-to-sccm-misconfiguration-abuse-50fa059a446eurl
- https://docs.ludus.cloud/docs/environment-guides/goad-sccm/url
- https://threathunterplaybook.com/hunts/windows/190810-RemoteWMIExecution/notebook.htmlurl
- https://mayfly277.github.io/posts/SCCM-LAB-part0x3/#execute-commandsurl
- https://www.paloaltonetworks.com/blog/security-operations/sccm-enterprise-backbone-or-attack-vector/url
- https://www.paloaltonetworks.com/blog/security-operations/sccm-enterprise-backbone-or-attack-vector-part-2/url
- https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/windows/defense_evasion_sccm_scnotification_dllurl
- https://www.netero1010-securitylab.com/red-team/abuse-sccm-remote-control-as-native-vncurl
- https://developers.openai.com/api/docs/models/gpt-5.6-solurl
- http://misconfigurationmanager.com/url
- dave@sccm.labemail