Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Misconfiguration-Manager — Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance. | Kitploit
Tools/GitHubGitHub/subat0mik/misconfiguration-manager
Defensive ToolsReconnaissanceVulnerability AnalysisLateral MovementConfiguration AuditingPenetration TestingMisconfigurationLearning & EducationRed Teaming

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Curated Resources
GitHubsubat0mik/misconfiguration-manager

Misconfiguration-Manager

Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.

View RepositoryWebsite
1.2k1172714 days agoReviewed by Kitploit
Share

Sponsored by SpecterOps Slack @subat0mik on Twitter @_Mayyhem on Twitter @unsigned_sh0rt on Twitter


Misconfiguration Manager

MM-cropped

Remediation Quick Start

  1. Review the list of known and documented Attack Techniques and corresponding Defense Techniques to identify issues that may be present in your environment and how to remediate them
    • Refer to this introduction to the project
  2. Run ConfigManBearPig and visualize the results in BloodHound for free
    • Refer to this walkthrough
  3. Alternatively, run MisconfigurationManager.ps1
    • Refer to this walkthrough
  4. Implement mitigations for identified misconfigurations
    • Refer to this walkthrough (or this recording (slides))

Overview

This repository serves as a central knowledge base for all known Microsoft Configuration Manager (a.k.a. MCM, ConfigMgr, System Center Configuration Manager, or SCCM) tradecraft and associated defensive and hardening guidance. Our goal is to help demystify SCCM tradecraft and simplify SCCM attack path management for defenders while also educating offensive security professionals on this nebulous attack surface. Designed to go beyond the static nature of whitepapers, this living repository documents known SCCM misconfigurations and their abuses and encourages ongoing contributions from the community to enhance its relevance and utility.

We've curated this repository to raise awareness of the rapidly evolving SCCM threat landscape, drawing inspiration from the MITRE ATT&CK framework, with a few deviations. We were also strongly influenced by Push Security's SaaS attack techniques matrix as well as Will Schroeder and Lee Chagolla-Christensen's Certified Pre-Owned whitepaper.

Our approach extends beyond cataloging the tactics of known adversaries to include contributions from the realm of penetration testing, red team operations, and security research. At SpecterOps, we've leveraged many misconfigurations highlighted in this repository in real-world environments, while others represent experimental and exploratory research projects proved out in a lab environment.

This project also serves as a central point of reference for all of the SCCM attack and defense resources that we're aware of.

We openly invite you to submit both proven and exploratory SCCM-focused attack techniques and defensive strategies and resources to this project and to provide any feedback and recommendations about the content in this repository.

For more of an introduction to the project, please reference our blog and conference talks:

  • Misconfiguration Manager: Overlooked and Overprivileged Blog Post
  • Misconfiguration Manager: Overlooked and Overprivileged (SO-CON 2024)
  • Misconfiguration Manager: Overlooked and Overprivileged (TROOPERS24)
  • Misconfiguration Manager: Still Overlooked, Still Overprivileged Blog Post


How to use this project

Refer to the SCCM Attack Matrix and SCCM Attack and Defense Matrix below, which map attack techniques to their MITRE ATT&CK framework tactics, as well as to their detection and prevention strategies.

Offensive security practitioners may also benefit from reviewing the list of known and documented Attack Techniques, which identifies the security context and network access that are required for each technique.

Defenders and IT administrators may benefit from reviewing the list of known and documented Defense Techniques, which identifies the administrator roles we think are most likely to be involved in the implementation of each item.

Curious about how a hierarchy can be completely compromised in certain, mostly default conditions? Check out the list of TAKEOVER techniques.

If you aren't familiar with a term used in a technique's description, refer to the glossary page, which contains definitions for terms commonly used in SCCM.

If you'd like to test these techniques in a lab environment or learn more about SCCM attack and defense, please refer to the resources page, which contains links to all the SCCM lab and attack/defense resources that we are aware of, many of which inspired and informed the information in this repository.

We've included a script that will audit many of the misconfigurations included in this repo. For more information about the script and how to use it, please reference our blog post.

If we've overlooked anything or are missing credits for prior work, please reach out to us or submit a pull request and we'd be happy to make updates.



SCCM Attack Matrix

Download Tool