| CRED‑1 | PXE Credentials | Retrieve secrets from PXE boot media | Unauthenticated | Internal network |
| CRED‑2 | Policy Request Credentials | Request machine policy and deobfuscate secrets | Domain computer creds | Internal network |
| CRED‑3 | DPAPI Credentials | Dump currently deployed secrets via WMI | Client device admin | Any |
| CRED‑4 | Legacy Credentials | Retrieve legacy secrets from the CIM repository | Client device admin | Any |
| CRED‑5 | Site Database Credentials | Retrieve credentials from the site database | Primary site server admin, site database read | Internal network |
| CRED‑6 | Looting Distribution Points | Loot Distribution Points via SMB or SCCM | Domain User or Unauthenticated (at times) | Any |
| CRED‑7 | AdminService API Credentials | Retrieve credentials via AdminService API | SCCM administrator | Internal network |
| ELEVATE‑1 | Relay to Site System (SMB) | NTLM relay site server to SMB on site systems | Domain user creds | Internal network |
| ELEVATE‑2 | Relay Client Push Installation | NTLM relay via automatic client push installation | Domain user creds | Internal network |
| ELEVATE‑3 | Relay Client Push Installation | NTLM relay via automatic client push installation and AD System Discovery | Domain user creds | Internal network |
| ELEVATE‑4 | PXE PKI Credentials | Distribution Point Takeover via PXE Boot Spoofing | Unauthenticated | Internal network |
| ELEVATE‑5 | OSD PKI Credentials | Distribution Point Takeover via OSD Media Recovery | Domain user creds | Internal network |
| EXEC‑1 | App Deployment | Application deployment | SCCM administrator | Internal network |
| EXEC‑2 | Script Deployment | PowerShell script execution | SCCM administrator | Internal network |
| RECON‑1 | LDAP Enumeration | Enumerate SCCM site information via LDAP | Authenticated domain user | Internal network |
| RECON‑2 | SMB Enumeration | Enumerate SCCM roles via SMB | Authenticated domain user | Internal network |
| RECON‑3 | HTTP Enumeration | Enumerate SCCM roles via HTTP | Authenticated domain user | Internal network |
| RECON‑4 | CMPivot | Query client devices via CMPivot | SCCM administrator | Internal network |
| RECON‑5 | SMS Provider Enumeration | Locate users via SMS Provider | SCCM administrator | Internal network |
| RECON‑6 | Remote Registry Enumeration | SCCM Site System Role Enumeration via Remote Registry | Authenticated domain user | Internal network |
| RECON‑7 | Local File Site Numeration | SCCM Site Enumeration via Local Files on Clients | Local admin on SCCM client | Internal network |
| TAKEOVER‑1 | Relay to Site DB (MSSQL) | NTLM coercion and relay to MSSQL on remote site database | Domain user creds | Internal network |
| TAKEOVER‑2 | Relay to Site DB (SMB) | NTLM coercion and relay to SMB on remote site database | Domain user creds | Internal network |
| TAKEOVER‑3 | Relay to AD CS | NTLM coercion and relay to HTTP on AD CS | Domain user creds | Internal network |
| TAKEOVER‑4 | Relay CAS to Child | NTLM coercion and relay from CAS to origin primary site server | Domain user creds | Internal network |
| TAKEOVER‑5 | Relay to AdminService | NTLM coercion and relay to AdminService on remote SMS Provider | Domain user creds | Internal network |
| TAKEOVER‑6 | Relay to SMS Provider (SMB) | NTLM coercion and relay to SMB on remote SMS Provider | Domain user creds | Internal network |
| TAKEOVER‑7 | Relay Between HA | NTLM coercion and relay to SMB between primary and passive site servers | Domain user creds | Internal network |
| TAKEOVER‑8 | Relay to LDAP | NTLM coercion and relay HTTP to LDAP on domain controller | Domain user creds | Internal network |
| TAKEOVER‑9 | SQL Linked as DBA | Crawl site database links configured with DBA privileges | Authenticated database user | Internal network |
| COERCE‑1 | CMPivot coercion | NTLM coercion via CMPivot query | CMPivot administrator | Internal network |
| COERCE‑2 | CcmExec Coercion | NTLM coercion via SCNotification AppDomainManager Injection | Local admin on SCCM client | Internal network |