
SCCM: The tree that always bears bad fruits | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 32:40
BLUF: A Synacktiv red teamer presents advanced exploitation techniques targeting the SCCM site database layer, moving beyond basic architecture and known misconfigurations to focus on SQL client interactions [0:00][0:46].
Key Takeaways:
• The speaker, a red teamer with 8 years of experience, previously presented on SCCM at Def Con 23 and Xinf Con, and released the SCCM SQL client tool [0:06][0:15].
• The session explicitly excludes basic SCCM architecture, roles, deployment fundamentals, and well-known abuse techniques [0:34][0:41].
• The primary focus is on advanced exploitation techniques that specifically target the site database layer [0:49].
This talk aims to deepen the understanding of SCCM security by exploring less documented database-level attack vectors.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Thank you for being here. Let's start. So, I'm going to quickly introduce myself. So, as I said, I'm a red teamer at Synacktiv. I've been I'm based in Paris, France. I've been working in the field for 8 years now. I spoke at Def Con 23 and Xif Con about SCCM. And now I'm going giving another talk to complete a bit the information that I shared previously. And [snorts] I released SCCM SQL client last year and entity sector. So, let's introduce this talk. Before I start, let me set the expectation for this session. So, I won't cover the SCCM basics like the architecture, the roles, and the deployment fundamentals. Nor I will cover the well-known misconfiguration and abuse techniques. But I will focus on advanced exploitation techniques targeting the site database layer. Also, trade craft tha…