Potential SCCM credential harvesting using WMI detected
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Microsoft SCCM Analytics
ATT&CK Tactic
Execution (TA0002), Credential Access (TA0006)
ATT&CK Technique
Windows Management Instrumentation (T1047), Unsecured Credentials (T1552)
Severity
Low
Description
Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM.
Attacker's Goals
Obtain credentials used by the SCCM service.
Investigative actions
Examine the process that executed the WMI query and the CGO and verify that the processes are from a trusted source.
Inspect the system for malicious activity that is related to that process.
Variations
Was this helpful?
