Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager. Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems. The access may be used to laterally move to other systems, gather information, or cause a specific effect, such as wiping the hard drives on all endpoints. SaaS-based configuration management services may allow for broad [Cloud Administration Command](https://attack.mitre.org/techniques/T1651) on cloud-hosted instances, as well as the execution of arbitrary commands on on-premises endpoints. For example, Microsoft Configuration Manager allows Global or Intune Administrators to run scripts as SYSTEM on on-premises devices joined to Entra ID.(Citation: SpecterOps Lateral Movement from Azure to On-Prem AD 2020) Such services may also utilize [Web Protocols](https://attack.mitre.org/techniques/T1071/001) to communicate back to adversary owned infrastructure.(Citation: Mitiga Security Advisory: SSM Agent as Remote Access Trojan) Network infrastructure devices may also have configuration management tools that can be similarly abused by adversaries.(Citation: Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation) The permissions required for this action vary by system configuration; local credentials may be sufficient with direct access to the third-party system, or specific domain credentials may be required. However, the system may require an administrative account to log in or to access specific functionality.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is part of Lateral Movement
is blocked by User Account Management
is blocked by Active Directory Configuration
is blocked by Update Software
is blocked by Privileged Account Management
is blocked by Password Policies
is blocked by Limit Software Installation
is blocked by Network Segmentation
is blocked by User Training
is blocked by Detection of Adversary Abuse of Software Deployment Tools
is blocked by Multi-factor Authentication
is blocked by Remote Data Storage
is blocked by Asset Inventories
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by User-Installed Software
is blocked by Continuous Monitoring
is blocked by Public Key Infrastructure (PKI)
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Authenticator Management
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Session Termination
is blocked by Cross Domain Solution (CDS)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Developer Configuration Management
is blocked by Third-Party Services
is blocked by Software & Firmware Patching
Impressum Deutsch Englisch