Skip to content

SCCM Indexing and Filelib Hash Resolution - #186

Closed
ZephrFish wants to merge 452 commits into
SnaffCon:masterfrom
ZephrFish:feature/sccm-clean
Closed

SCCM Indexing and Filelib Hash Resolution#186
ZephrFish wants to merge 452 commits into
SnaffCon:masterfrom
ZephrFish:feature/sccm-clean

Conversation

@ZephrFish

@ZephrFish ZephrFish commented Jan 31, 2026

Copy link
Copy Markdown
Contributor

Needs more testing in broader environments HOWEVER this is working in my home lab with 8 machines

Re-submitting because computers were a mistake and git broke in my VM 💯

Add SCCM integration with automatic discovery and content library resolution:

  • Implement SCCM share discovery (SCCMContentLib$, SCCM$, etc.)
  • Add content library file hash resolution using DataLib index
  • Support for INI-based content hash lookups and file mapping
  • LRU cache for efficient repeated hash resolutions
  • Detection rules for SCCM deployment packages and content files
  • Hash resolution logic borrowed from CMLoot for accurate file identification, if you're curious about the logic I read the blog post originally here then found the tool

New components:

  • SCCMDiscovery.cs: Automatic SCCM share enumeration
  • SCCMContentLibResolver.cs: Content library hash resolution
  • SCCMFileMapping.cs: File path to content hash mapping
  • LRUCache.cs: Caching layer for performance
  • KeepSCCMContentFiles.toml: Detection rule for SCCM content

Integration points:

  • ShareFinder: SCCM share detection and prioritization
  • TreeWalker: SCCM-aware file enumeration
  • FileClassifier: SCCM content identification

.NET Framework updates:

  • Update TargetFrameworkVersion to v4.5.1 match SnaffCore.csproj
  • Resolves CI build compatibility issues

ZephrFish added 30 commits June 15, 2021 09:11
fixed up some noisy rules, made Main() public so can load with ps ref…
Fixed false positives stemming from 'net user?' regex
Fixed horrible false-pos rule in ruby code.
…his code because I'm bad at git. Sorry mate.
…nd is accurate and distinguishes between write and modify!
…t in the ultrasnaffler merge somehow."

This reverts commit 7098942.
ZephrFish and others added 28 commits October 11, 2024 17:07
Additional detection of unquoted credentials which are used with for example the parameter -password
Changing the rule identifying client secrets to identify unquoted secrets as well.
Change an existing rule to find more candy.
Additional regex in KeepPassOrKeyInCode.toml
…rgetIPList

Add ReverseDNSLookup in SnaffCon.cs to fix SnaffCon#161 for named target IPs
added .ucs file extension for F5 appliance backups, cheers plugger!
Update KeepInfraAsCodeConfigByExtension.toml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Fix for passing target Domain without target DC or DC as FQDN instead of IP - also made -i accept comma separated list
Added a rule to look for common virtual machine disk files.
… my home lab with 8 machines

Add SCCM integration with automatic discovery and content library resolution:

- Implement SCCM share discovery (SCCMContentLib$, SCCM$, etc.)
- Add content library file hash resolution using DataLib index
- Support for INI-based content hash lookups and file mapping
- LRU cache for efficient repeated hash resolutions
- Detection rules for SCCM deployment packages and content files
- Hash resolution logic borrowed from [CMLoot](https://github.com/shelltrail/cmloot) for accurate file identification, if you're curious about the logic I [read the blog post originally here](https://www.shelltrail.com/research/cmloot/) then found the tool

New components:
- SCCMDiscovery.cs: Automatic SCCM share enumeration
- SCCMContentLibResolver.cs: Content library hash resolution
- SCCMFileMapping.cs: File path to content hash mapping
- LRUCache.cs: Caching layer for performance
- KeepSCCMContentFiles.toml: Detection rule for SCCM content

Integration points:
- ShareFinder: SCCM share detection and prioritization
- TreeWalker: SCCM-aware file enumeration
- FileClassifier: SCCM content identification

.NET Framework updates:
- Update TargetFrameworkVersion from v4.5.1 to v4.8 to match SnaffCore.csproj
- Resolves CI build compatibility issues
Create KeepVMDisksByExtension.toml
- Updated SnaffCore.csproj from v4.8 to v4.5.1
- Updated Snaffler.csproj from v4.8 to v4.5.1
- Updated app.config runtime version to v4.5.1
- Ensures compatibility with systems running .NET Framework 4.5+
- All SCCM functionality and NuGet packages verified compatible
SCCM ContentLib scan with original filename
@ZephrFish ZephrFish closed this Jul 30, 2026
@ZephrFish
ZephrFish force-pushed the feature/sccm-clean branch from 59dd078 to e61cbdf Compare July 30, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant