Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1482 Domain Trust Discovery |
MalwareTrickBot | TrickBot can gather information about domain trusts by utilizing Nltest. |
| T1482 Domain Trust Discovery |
MalwarePikabot | Pikabot will gather information concerning the Windows Domain the victim machine is a member of during execution. |
| T1482 Domain Trust Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify Active Directory information and related items. |
| T1482 Domain Trust Discovery |
MalwareBADHATCH | BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine. |
| T1482 Domain Trust Discovery |
MalwareIcedID | |
| T1482 Domain Trust Discovery |
MalwareSocGholish | SocGholish can profile compromised systems to identify domain trust relationships. |
| T1482 Domain Trust Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts. |
| T1482 Domain Trust Discovery |
MalwareBazar | Bazar can use Nltest tools to obtain information about the domain. |
| T1482 Domain Trust Discovery |
MalwareMgBot | MgBot includes modules for collecting information on local domain users and permissions. |
| T1482 Domain Trust Discovery |
MalwareLAMEHUG | LAMEHUG can gather Active Directory domain information. |
| T1482 Domain Trust Discovery |
MalwareQakBot | QakBot can run |
| T1482 Domain Trust Discovery |
ToolBloodHound | BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse. |
| T1482 Domain Trust Discovery |
ToolPowerSploit | PowerSploit has modules such as |
| T1482 Domain Trust Discovery |
ToolEmpire | Empire has modules for enumerating domain trusts. |
| T1482 Domain Trust Discovery |
Tooldsquery | dsquery can be used to gather information on domain trusts with |
| T1482 Domain Trust Discovery |
ToolPoshC2 | PoshC2 has modules for enumerating domain trusts. |
| T1482 Domain Trust Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery. |
| T1482 Domain Trust Discovery |
ToolNltest | Nltest may be used to enumerate trusted domains by using commands such as |
| T1482 Domain Trust Discovery |
ToolRubeus | Rubeus can gather information about domain trusts. |
| T1482 Domain Trust Discovery |
ToolAdFind | AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.