Description
This module creates an SMB server and then relays the credentials passed to it to SCCM's HTTP server (aka Management Point) to gain an authenticated connection. Once authenticated it then attempts to retrieve the Network Access Account(s), if configured, from the SCCM server. This requires a computer account, which can be added using the samr_account module.
If you have domain credentials but are unsure of the either the MANAGEMENT_POINT or SITE_CODE for the SCCM server, the original (non-relay) version of this module has an auto discovery feature which will use domain credentials to run an LDAP query to find both the MANAGEMENT_POINT and the SITE_CODE.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/server/relay/relay/get_naa_credentialsmsf undefined(get_naa_credentials) > show actions ...actions...msf undefined(get_naa_credentials) > set ACTION < action-name >msf undefined(get_naa_credentials) > show options ...show and set options...msf undefined(get_naa_credentials) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub