> ## Documentation Index
> Fetch the complete documentation index at: https://docs.specterops.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

| Codename                                                   | Matrix Shortname               | Description                                                               | Security Context                              | Network Access   |
| ---------------------------------------------------------- | ------------------------------ | ------------------------------------------------------------------------- | --------------------------------------------- | ---------------- |
| [CRED‑1](./CRED/CRED-1/cred-1_description)                 | PXE Credentials                | Retrieve secrets from PXE boot media                                      | Unauthenticated                               | Internal network |
| [CRED‑2](./CRED/CRED-2/cred-2_description)                 | Policy Request Credentials     | Request machine policy and deobfuscate secrets                            | Domain computer creds                         | Internal network |
| [CRED‑3](./CRED/CRED-3/cred-3_description)                 | DPAPI Credentials              | Dump currently deployed secrets via WMI                                   | Client device admin                           | Any              |
| [CRED‑4](./CRED/CRED-4/cred-4_description)                 | Legacy Credentials             | Retrieve legacy secrets from the CIM repository                           | Client device admin                           | Any              |
| [CRED‑5](./CRED/CRED-5/cred-5_description)                 | Site Database Credentials      | Retrieve credentials from the site database                               | Primary site server admin, site database read | Internal network |
| [CRED‑6](./CRED/CRED-6/cred-6_description)                 | Looting Distribution Points    | Loot Distribution Points via SMB or SCCM                                  | Domain User or Unauthenticated (at times)     | Any              |
| [CRED‑7](./CRED/CRED-7/cred-7_description)                 | AdminService API Credentials   | Retrieve credentials via AdminService API                                 | SCCM administrator                            | Internal network |
| [ELEVATE‑1](./ELEVATE/ELEVATE-1/ELEVATE-1_description)     | Relay to Site System (SMB)     | NTLM relay site server to SMB on site systems                             | Domain user creds                             | Internal network |
| [ELEVATE‑2](./ELEVATE/ELEVATE-2/ELEVATE-2_description)     | Relay Client Push Installation | NTLM relay via automatic client push installation                         | Domain user creds                             | Internal network |
| [ELEVATE‑3](./ELEVATE/ELEVATE-3/ELEVATE-3_description)     | Relay Client Push Installation | NTLM relay via automatic client push installation and AD System Discovery | Domain user creds                             | Internal network |
| [ELEVATE‑4](./ELEVATE/ELEVATE-4/ELEVATE-4_description)     | PXE PKI Credentials            | Distribution Point Takeover via PXE Boot Spoofing                         | Unauthenticated                               | Internal network |
| [ELEVATE‑5](./ELEVATE/ELEVATE-5/ELEVATE-5_description)     | OSD PKI Credentials            | Distribution Point Takeover via OSD Media Recovery                        | Domain user creds                             | Internal network |
| [EXEC‑1](./EXEC/EXEC-1/exec-1_description)                 | App Deployment                 | Application deployment                                                    | SCCM administrator                            | Internal network |
| [EXEC‑2](./EXEC/EXEC-2/exec-2_description)                 | Script Deployment              | PowerShell script execution                                               | SCCM administrator                            | Internal network |
| [RECON‑1](./RECON/RECON-1/recon-1_description)             | LDAP Enumeration               | Enumerate SCCM site information via LDAP                                  | Authenticated domain user                     | Internal network |
| [RECON‑2](./RECON/RECON-2/recon-2_description)             | SMB Enumeration                | Enumerate SCCM roles via SMB                                              | Authenticated domain user                     | Internal network |
| [RECON‑3](./RECON/RECON-3/recon-3_description)             | HTTP Enumeration               | Enumerate SCCM roles via HTTP                                             | Authenticated domain user                     | Internal network |
| [RECON‑4](./RECON/RECON-4/recon-4_description)             | CMPivot                        | Query client devices via CMPivot                                          | SCCM administrator                            | Internal network |
| [RECON‑5](./RECON/RECON-5/recon-5_description)             | SMS Provider Enumeration       | Locate users via SMS Provider                                             | SCCM administrator                            | Internal network |
| [RECON‑6](./RECON/RECON-6/recon-6_description)             | Remote Registry Enumeration    | SCCM Site System Role Enumeration via Remote Registry                     | Authenticated domain user                     | Internal network |
| [RECON‑7](./RECON/RECON-7/recon-7_description)             | Local File Site Numeration     | SCCM Site Enumeration via Local Files on Clients                          | Local admin on SCCM client                    | Internal network |
| [TAKEOVER‑1](./TAKEOVER/TAKEOVER-1/takeover-1_description) | Relay to Site DB (MSSQL)       | NTLM coercion and relay to MSSQL on remote site database                  | Domain user creds                             | Internal network |
| [TAKEOVER‑2](./TAKEOVER/TAKEOVER-2/takeover-2_description) | Relay to Site DB (SMB)         | NTLM coercion and relay to SMB on remote site database                    | Domain user creds                             | Internal network |
| [TAKEOVER‑3](./TAKEOVER/TAKEOVER-3/takeover-3_description) | Relay to AD CS                 | NTLM coercion and relay to HTTP on AD CS                                  | Domain user creds                             | Internal network |
| [TAKEOVER‑4](./TAKEOVER/TAKEOVER-4/takeover-4_description) | Relay CAS to Child             | NTLM coercion and relay from CAS to origin primary site server            | Domain user creds                             | Internal network |
| [TAKEOVER‑5](./TAKEOVER/TAKEOVER-5/takeover-5_description) | Relay to AdminService          | NTLM coercion and relay to AdminService on remote SMS Provider            | Domain user creds                             | Internal network |
| [TAKEOVER‑6](./TAKEOVER/TAKEOVER-6/takeover-6_description) | Relay to SMS Provider (SMB)    | NTLM coercion and relay to SMB on remote SMS Provider                     | Domain user creds                             | Internal network |
| [TAKEOVER‑7](./TAKEOVER/TAKEOVER-7/takeover-7_description) | Relay Between HA               | NTLM coercion and relay to SMB between primary and passive site servers   | Domain user creds                             | Internal network |
| [TAKEOVER‑8](./TAKEOVER/TAKEOVER-8/takeover-8_description) | Relay to LDAP                  | NTLM coercion and relay HTTP to LDAP on domain controller                 | Domain user creds                             | Internal network |
| [TAKEOVER‑9](./TAKEOVER/TAKEOVER-9/takeover-9_description) | SQL Linked as DBA              | Crawl site database links configured with DBA privileges                  | Authenticated database user                   | Internal network |
| [COERCE‑1](./COERCE/COERCE-1/coerce-1_description)         | CMPivot coercion               | NTLM coercion via CMPivot query                                           | CMPivot administrator                         | Internal network |
| [COERCE‑2](./COERCE/COERCE-2/coerce-2_description)         | CcmExec Coercion               | NTLM coercion via SCNotification AppDomainManager Injection               | Local admin on SCCM client                    | Internal network |
