BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: SharpSCCM\n   When: Saturday\, Aug 13\, 12:00 - 13:5
 5 PDT\n   Where: Caesars Forum - Society Boardroom (Demo Labs) - [1]Map\n 
   Speakers:Chris Thompson\,Duane Michael\n\n   SpeakerBio:Chris Thompson\n
    Chris is a senior consultant on SpecterOps’s adversary simulation\n  
  team and has over ten years of experience in information security\,\n   s
 erving numerous Fortune 500 clients in the retail\, consumer products\,\n 
   financial\, and telecom industries. He has extensive experience leading\
 n   network\, web application\, and wireless penetration tests\, social\n 
   engineering engagements\, and technical security assessments to provide\
 n   actionable recommendations that align with each organization's\n   sec
 urity strategy and risk tolerance. Chris enjoys researching and\n   applyi
 ng new tradecraft to overcome technical challenges and writing\n   tools t
 hat automate tasks and improve efficiency.\n\n   SpeakerBio:Duane Michael\
 n   Duane is a senior consultant on SpecterOps's adversary simulation\n   
 team\, where he conducts advanced red team exercises and instructs\n   cou
 rses on red team operations and vulnerability research. He has over\n   te
 n years of experience in information security\, with a deep curiosity\n   
 for researching Windows\, its internals\, and related technologies.\n   Du
 ane strives to demystify tradecraft for clients through both an\n   offens
 ive and defensive lens\, an activity he has performed for\n   numerous For
 tune 100 clients.\n\n   Description:\n   SharpSCCM is a post-exploitation 
 tool designed to leverage Microsoft\n   Endpoint Configuration Manager (a.
 k.a. ConfigMgr\, formerly SCCM) for\n   lateral movement from a C2 agent w
 ithout requiring access to the SCCM\n   administration console. SharpSCCM 
 supports lateral movement functions\n   ported from PowerSCCM and contains
  additional functionality to abuse\n   newly discovered attack primitives 
 for coercing NTLM authentication\n   from local administrator and SCCM sit
 e server machine accounts in\n   environments where automatic client push 
 installation is enabled.\n   SharpSCCM can also dump information about the
  SCCM environment from a\n   client\, including domain credentials for Net
 work Access Accounts.\n   Further\, with access to an SCCM administrator a
 ccount\, operators of\n   SharpSCCM can execute code as SYSTEM or coerce N
 TLM authentication\n   from the currently logged-in user or the machine ac
 count on any SCCM\n   client.\n\n   Audience: Offense\, Defense\, System A
 dministrators\n\n   '\n\n   1. https://defcon.outel.org/consolidated_page.
 html#CaesarsSummitBR\n\n\n
DTEND:20220813T205500Z
DTSTART:20220813T190000Z
LOCATION:DL - Caesars Forum - Society Boardroom (Demo Labs)
SUMMARY:SharpSCCM
END:VEVENT
END:VCALENDAR
