.\SharpSCCM.exe local triage
_______ _ _ _______ ______ _____ _______ _______ _______ _______
|______ |_____| |_____| |_____/ |_____] |______ | | | | |
______| | | | | | \_ | ______| |______ |______ | | | @_Mayyhem
[+] Client cache contents and permissions for the current user:
Perms Size Date modified Name
drw 8/31/2024 1:51:07 AM C:\Windows\ccmcache
-rw 0.0B 8/31/2024 1:51:07 AM C:\Windows\ccmcache\skpswi.dat
[+] Searching logs for possible UNC paths:
Found match in C:\Windows\CCM\Logs\InventoryAgent-20241019-033813.log
\\localhost\root\cimv2
\\localhost\root\vm\VirtualServer
\\localhost\root\vm\VirtualServer Namespace
\\localhost\root\Microsoft\appvirt\client
\\localhost\root\Microsoft\appvirt\client Namespace
Found match in C:\Windows\CCM\Logs\InventoryAgent.log
\\localhost\root\cimv2
\\localhost\root\vm\VirtualServer
\\localhost\root\vm\VirtualServer Namespace
[+] Searching logs for possible URLs:
Found match in C:\Windows\CCM\Logs\CcmEval-20241020-204501.log
http://atlas.aperture.local
Found match in C:\Windows\CCM\Logs\CcmEval.log
http://atlas.aperture.local
Found match in C:\Windows\CCM\Logs\CcmMessaging-20241020-062929.log
http://atlas.aperture.local/CCM_Incoming/
http://atlas.aperture.local:80/CCM_Incoming/
Found match in C:\Windows\CCM\Logs\CcmMessaging.log
http://atlas.aperture.local/CCM_Incoming/
http://atlas.aperture.local:80/CCM_Incoming/
Found match in C:\Windows\CCM\Logs\ClientLocation.log
http://atlas.aperture.local
Found match in C:\Windows\CCM\Logs\ClientServicing.log
http://atlas.aperture.local
http://atlas.aperture.local/CCM_Client
Found match in C:\Windows\CCM\Logs\DataTransferService.log
http://atlas.aperture.local/SMS_MP
http://atlas.aperture.local:80/SMS_MP
Found match in C:\Windows\CCM\Logs\DeltaDownload-20241012-184715.log
http://localhost:8005
Found match in C:\Windows\CCM\Logs\DeltaDownload.log
http://localhost:8005
Found match in C:\Windows\CCM\Logs\SensorEndpoint-20241023-173719.log
http://www.w3.org/2001/XMLSchema
http://www.w3.org/2001/XMLSchema-instance
http://schemas.microsoft.com/win/2004/08/events/event
Found match in C:\Windows\CCM\Logs\SensorEndpoint.log
http://www.w3.org/2001/XMLSchema
http://www.w3.org/2001/XMLSchema-instance
http://schemas.microsoft.com/win/2004/08/events/event
Found match in C:\Windows\CCM\Logs\SensorManagedProvider-20241024-144230.Log
http://www.w3.org/2001/XMLSchema-instance
http://www.w3.org/2001/XMLSchema
Found match in C:\Windows\CCM\Logs\SensorManagedProvider.Log
http://www.w3.org/2001/XMLSchema-instance
http://www.w3.org/2001/XMLSchema
[+] Completed execution in 00:00:09.8748192