Technique.View on attack.mitre.org
Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.
Rules on DetectionCode tagged with T1482.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect AzureHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect AzureHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect SharpHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| DSQuery Domain Discovery | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get-DomainTrust with PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get-DomainTrust with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Get-ForestTrust with PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get-ForestTrust with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Network Traffic to Active Directory Web Services Protocol | Hunting | NULL | Sysmon EventID 3 |
| NLTest Domain Trust Discovery | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows SOAPHound Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAkira | Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments. |
| GroupBlackByte | BlackByte enumerated Active Directory information and trust relationships during operations. |
| GroupChimera | Chimera has |
| GroupEarth Lusca | Earth Lusca has used Nltest to obtain information about domain controllers. |
| GroupFIN8 | FIN8 has retrieved a list of trusted domains by using |
| GroupLotus Blossom | Lotus Blossom has used tools such as AdFind to make Active Directory queries. |
| GroupMagic Hound | Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships. |
| GroupMirrorFace | MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships. |
| Used by | Procedure example |
|---|---|
| ToolAdFind | AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory. |
| MalwareBADHATCH | BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine. |
| MalwareBazar | Bazar can use Nltest tools to obtain information about the domain. |
| ToolBloodHound | BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse. |
| ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery. |
| Tooldsquery | dsquery can be used to gather information on domain trusts with |
| MalwareDUSTTRAP | DUSTTRAP can identify Active Directory information and related items. |
| ToolEmpire | Empire has modules for enumerating domain trusts. |
| Used by | Procedure example |
|---|---|
| CampaignC0015 | During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts. |
| CampaignLeviathan Australian Intrusions | Leviathan performed Active Directory enumeration of victim environments during Leviathan Australian Intrusions. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.