The Admin's Guide to Preventing SCCM Attacks | SO-CON 2025

The Admin's Guide to Preventing SCCM Attacks | SO-CON 2025

Source: YouTube · SpecterOps · published May 8, 2025 · 51:35

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video introduces Misconfiguration Manager, a tool developed by Specter Ops researchers to track and manage common security misconfigurations, particularly in cloud environments 0:10.

Key Takeaways:
• The speaker, Chris Thompson, is a senior security researcher at Specter Ops who contributed to the development of SharpSCCM and Misconfiguration Manager 0:25.
• Misconfiguration Manager serves as a repository for tracking techniques and tools used to identify security vulnerabilities and misconfigurations 0:44.
• A QR code is provided for attendees to download slides from misconfigurationmanager.com, which includes content labeled "so 2022" 0:08.
• The tool was created in collaboration with Garrett and Dwayne to systematically document techniques encountered during security operations 0:42.

This presentation highlights the importance of centralized resources for managing cloud security risks and shares insights from practical offensive security experiences.

Sources:

  • 0:10 Introduction of Misconfiguration Manager and slides availability
  • 0:25 Speaker's background at Specter Ops
  • 0:44 Purpose of Misconfiguration Manager
  • 0:08 QR code for slide download
  • 0:42 Collaboration on tracking security techniques

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] Cool. Well, thanks for coming. Um, there's a QR code at the top if you want to like download a copy of the slides. It'll take you to misconfiguration manager.com. Um, there's a copy of the slides there labeled so 2022 if you want to check it out. Um, and look through kind of some of the other techniques that we'll be talking about today. So, I'm Chris Thompson. I'm a senior security researcher at Spectre Ops. I've been working here for about four years. Um, kind of got into attacking SECM on an op. Uh, needed to find a particular user, execute code on their machine. Ended up writing Sharp SECM. And then Garrett, me and Dwayne wrote, uh, Misconfiguration Manager to kind of track a lot of these techniques that we were coming across um, because it was hard to remember all of them. I a…