T1482 Domain Trust Discovery — ATT&CK Technique
Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.
Detection coverage (31)
- PUA - AdFind Suspicious Execution high
- Potential Active Directory Reconnaissance/Enumeration Via LDAP medium
- DNS Server Discovery Via LDAP Query low
- BloodHound Collection Files high
- ADExplorer Writing Complete AD Snapshot Into .dat File medium
- Malicious PowerShell Commandlets - PoshModule high
- Malicious PowerShell Commandlets - ScriptBlock high
- Domain Trust Discovery Via Dsquery medium
- HackTool - Bloodhound/Sharphound Execution high
- HackTool - SharpView Execution high
- HackTool - TruffleSnout Execution high
- Potential Recon Activity Via Nltest.EXE medium
- Nltest.EXE Execution low
- Malicious PowerShell Commandlets - ProcessCreation high
- Renamed AdFind Execution high
- Suspicious Active Directory Database Snapshot Via ADExplorer high
- Active Directory Database Snapshot Via ADExplorer medium
- Detect AzureHound Command-Line Arguments
- Detect AzureHound File Modifications
- Detect SharpHound Command-Line Arguments
- Detect SharpHound File Modifications
- Detect SharpHound Usage
- DSQuery Domain Discovery
- Get-DomainTrust with PowerShell
- Get-DomainTrust with PowerShell Script Block
- Get-ForestTrust with PowerShell
- Get-ForestTrust with PowerShell Script Block
- Network Traffic to Active Directory Web Services Protocol
- NLTest Domain Trust Discovery
- Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
- Windows SOAPHound Binary Execution
Malware using this technique
- Empire
- Bazar
- IcedID
- Pikabot
- AdFind
- Rubeus
- SocGholish
- LAMEHUG
- MgBot
- Nltest
- QakBot
- Brute Ratel C4
- BloodHound
- Latrodectus
- BADHATCH
- DUSTTRAP
- PoshC2
- dsquery
- PowerSploit
- TrickBot