TGViewer
RedTeam feed RedTeam feed @redteamfeed · 602 subscribers
Post #1664 227
Unmasking SCCM Application Execution
#specterops

TL;DR: Executing applications instead of scripts via SCCM’s deploy application feature will generate different artifacts due to the fundamental differences in the execution flow. While existing detection tools can catch script-based execution, they often miss stealthier methods. This post covers how to detect the more evasive SCCM application execution. Introduction: During BlackHat 2025’s offering of […]

The post Unmasking SCCM Application Execution appeared first on SpecterOps.

via SpecterOps Blog (author: Joshua Prager)
More from @redteamfeed
  1. Sep 24, 2026What's New in hate_crack Since 2.0 #trustedsec &LTp>Part 1 of 3. This post is the referenc…
  2. Sep 23, 2026HTTP/3 in Burp Suite - it’s time to find a bigger wordlist #portswigger How many bugs have…
  3. Sep 18, 2026From Fork to Framework: What Modifying Apollo Taught Us About Agent Invasion #bishopfox Fo…
  4. Sep 17, 2026MikroTrick: Inside the RouterOS Takeover Chain #bishopfox Attackers were exploiting MikroT…
  5. Sep 17, 2026CiliumHound: Graphing Kubernetes Network Policies #specterops TLDR: CiliumHound is a Blood…
  6. Sep 17, 2026Unpacking a laZzzy Donut #trustedsec Recently, we came across an interesting malware sampl…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →