Domain Trust Discovery

T1482

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.

Detection rules31

Rules on DetectionCode tagged with T1482.

Sigma17

RuleLevelLog source
BloodHound Collection Fileshighwindows / file_event
HackTool - Bloodhound/Sharphound Executionhighwindows / process_creation
HackTool - SharpView Executionhighwindows / process_creation
HackTool - TruffleSnout Executionhighwindows / process_creation
Malicious PowerShell Commandlets - PoshModulehighwindows / ps_module
Malicious PowerShell Commandlets - ProcessCreationhighwindows / process_creation
Malicious PowerShell Commandlets - ScriptBlockhighwindows / ps_script
PUA - AdFind Suspicious Executionhighwindows / process_creation
Renamed AdFind Executionhighwindows / process_creation
Suspicious Active Directory Database Snapshot Via ADExplorerhighwindows / process_creation
Active Directory Database Snapshot Via ADExplorermediumwindows / process_creation
ADExplorer Writing Complete AD Snapshot Into .dat Filemediumwindows / file_event
Domain Trust Discovery Via Dsquerymediumwindows / process_creation
Potential Active Directory Reconnaissance/Enumeration Via LDAPmediumwindows / NULL
Potential Recon Activity Via Nltest.EXEmediumwindows / process_creation

Splunk14

RuleTypeRiskData source
Detect AzureHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect AzureHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect SharpHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
DSQuery Domain DiscoveryTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get-DomainTrust with PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get-DomainTrust with PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
Get-ForestTrust with PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get-ForestTrust with PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
Network Traffic to Active Directory Web Services ProtocolHuntingNULLSysmon EventID 3
NLTest Domain Trust DiscoveryTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell ScriptTTPNULLPowershell Script Block Logging 4104
Windows SOAPHound Binary ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups10

Software20

Campaigns3

Procedure examples33

Groups10

Used byProcedure example
GroupAkira

Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.

GroupBlackByte

BlackByte enumerated Active Directory information and trust relationships during operations.

GroupChimera

Chimera has nltest /domain_trusts to identify domain trust relationships.

GroupEarth Lusca

Earth Lusca has used Nltest to obtain information about domain controllers.

GroupFIN8

FIN8 has retrieved a list of trusted domains by using nltest.exe /domain_trusts.

GroupLotus Blossom

Lotus Blossom has used tools such as AdFind to make Active Directory queries.

GroupMagic Hound

Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships.

GroupMirrorFace

MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships.

View all 10 groups examples

Software20

Used byProcedure example
ToolAdFind

AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.

MalwareBADHATCH

BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine.

MalwareBazar

Bazar can use Nltest tools to obtain information about the domain.

ToolBloodHound

BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse.

ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery.

Tooldsquery

dsquery can be used to gather information on domain trusts with dsquery * -filter "(objectClass=trustedDomain)" -attr *.

MalwareDUSTTRAP

DUSTTRAP can identify Active Directory information and related items.

ToolEmpire

Empire has modules for enumerating domain trusts.

View all 20 software examples

Campaigns3

Used byProcedure example
CampaignC0015

During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts.

CampaignLeviathan Australian Intrusions

Leviathan performed Active Directory enumeration of victim environments during Leviathan Australian Intrusions.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains.

References4

  1. AdSecurity Forging Trust Tickets Open source
    Metcalf, S. (2015, July 15). It’s All About Trust – Forging Kerberos Trust Tickets to Spoof Access across Active Directory Trusts. Retrieved February 14, 2019.
  2. Harmj0y Domain Trusts Open source
    Schroeder, W. (2017, October 30). A Guide to Attacking Domain Trusts. Retrieved February 14, 2019.
  3. Microsoft Operation Wilysupply Open source
    Florio, E.. (2017, May 4). Windows Defender ATP thwarts Operation WilySupply software supply chain cyberattack. Retrieved February 14, 2019.
  4. Microsoft Trusts Open source
    Microsoft. (2009, October 7). Trust Technologies. Retrieved February 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.