Cole_McDonald
6 years agoProfessor
!!! Collector Debug Console Security !!!
In doing some of the troubleshooting with LM, I realized that the debug console opens !POSH sessions as admin without asking or verifying. Anyone that can log into the console and gain access to the collector to run a debug has default admin access into our environment. The debug console can run Powershell commands on the collector server as if you had opened a powershell console as administrator locally. From there, I can easily push an elevated command anywhere using CredSSP delegation as a second hop credential option leveraging the credentials given to the collector.