Hey friends! We’ve been on a bit of a Tales of Pentest Pwnage bender lately, so let’s keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is less of an A-to-Z story and more a pile of tips and tricks pulled from a recent string of SCCM-flavored internals — plus a tangent about a video game and a little robot Claude and I built to get my life back.

  • Multi-tier SCCM is having a moment — I’ve never administered SCCM a day in my life, but 2026 keeps dropping me into these split-role environments. Here’s where I go to figure out my attack surface when all I’ve got is a low-priv cred.
  • SMB signing on? Cool, I’ll go around it — relaying from one SCCM box to the one with SQL on it, and the easy-button tool that vacuums the good stuff out of the database once you’re there. (NAA creds, clear-text local admin passwords, install scripts with creds baked in…yes please.)
  • Then relay the other direction — when the loot came back stale, a nudge from a Slack channel had me pointing the relay backwards, and I giggled like a little schoolboy at what popped out.
  • Adding yourself to the local admin group: still weirdly undetected — an old episode of ours reminded me of an Impacket tool I don’t see written up on many pentest blogs, and it slipped right by.
  • My favorite cheat code hit a snag — the evil-scheduled-task-under-a-logged-in-DA trick kept coughing up permission errors, so I had to get creative. Plus the defensive recs I’m still trying to sharpen up — if you’ve got a better way to close this loophole, I’m all ears!
  • Tangent: Halloween (the video game) and the lobby watcher — a million players and I’m still staring into the lobby abyss for 10 minutes at a time. So Claude and I built something that watches the screen and texts me when it’s time to sprint back to the keyboard. It’s not cheating. It’s not! (The Texas Chainsaw crowd disagreed, loudly.)

Written by: Brian Johnson

Share on socials: