Exposing SCCM and MSSQL Attack Paths in Hardened Environments with OpenGraph | SO-CON 26

Exposing SCCM and MSSQL Attack Paths in Hardened Environments with OpenGraph | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 45:59

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This presentation introduces SECM tradecraft and two custom open graph collectors designed to enhance offensive security operations 0:04-0:20.

Key Takeaways:
• The talk covers the foundational architecture of SECM attacks to establish a baseline understanding of how these threats operate 0:04-0:13.
• The speaker details two open graph collectors he developed, sharing practical lessons learned and how to integrate them into operations 0:15-0:20.
• Presenter Chris Thompson is a Senior Security Researcher at Specter Ops who focuses on tool development and security training 0:23-0:31.
• The session begins with a crash course on SECM concepts to properly set the stage for the technical tooling discussions 0:41-0:44.

While the provided transcript is truncated, the core focus of the talk is clearly bridging the gap between SECM attack theory and practical tool development for red teamers.

Sources:

  • 0:04-0:20 Introduction to SECM tradecraft and open graph collectors
  • 0:15-0:20 Overview of the two custom tools and operational lessons
  • 0:23-0:31 Speaker background and affiliation with Specter Ops
  • 0:41-0:44 Transition into the SECM crash course

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Cool. So, yeah, uh quite a mouthful of a title. We're going to talk a bit about uh SECM Tradecraft as kind of like an intro to make sure everybody's on the same page in terms of like the architecture of how these attacks came to be. And then we'll talk about two open graph collectors that I wrote, some kind of lessons I learned from them, and how you can use them uh in your operations. So, a little bit about me. My name is Chris Thompson. I'm a senior security researcher at Spectre Ops. I write a lot of tools, uh, contribute to a lot of tools, do training. If you want to get in touch with me, you can scan this QR code if you trust me, uh, or hit me up on the Blood Hound Slack. So, to start out, we're going to do a little SECM crash course. Um, introduce a lot of the concepts that allow com…