Attack on SCOM: From Domain User to Code Execution
Attack Techniques & Methods2026-09-10, 11:18
The research shows that the default configuration of Microsoft System Center Operations Manager (SCOM) can be used to execute code on all managed hosts. The attack uses relay: an attacker with a standard domain account intercepts Data Access Service authentication and adds themselves to the list of SCOM administrators, gaining access to the Operations Console.
SCOM then becomes a centralized attack management platform: the console can be used to execute commands on all connected servers, while Run As and Action Account credentials can be extracted from agents. As a result, compromising a single domain user can lead to complete control over the monitoring infrastructure and all managed systems.
Vendors
Products