Domain Trust Discovery T1482

Tactic: Discovery

Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.

Events covered

17 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 66 rules share fields, values, and exclusions.

Fields filtered most (44 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine23contains 17, regex_match 4, in 2 oudmp , (?i)(objectcategory|trustdmp|member\s(.*)?-list), -sc u:, trusteddomain, --collectionmethods session
EventID14eq 144104, 4688, 4103, 4662, 4799
OriginalFileName14eq 14adexp, nltestrk.exe, adfind.exe, dsquery.exe, sharphound.exe
Image13ends_with 11, contains 2, eq 2, is_null 1, starts_with 1\adexp.exe, \adexplorer.exe, \adexplorer64.exe, \nltest.exe, :\program files (x86)\
process_name10eq 8, wildcard 2dsquery.exe, nltest.exe, adexplorer*.exe, adfind*.exe, arp.exe
ScriptBlockText8contains 5, in 3, eq 1.getgporeport(), ::getipglobalproperties(), ::getprocesses, add-constraineddelegationbackdoor, add-domaingroupmember
process.Ext.api.name8eq 8ldap_search
process.Ext.api.parameters.search_filter8eq 4, wildcard 4(&(&(objectCategory=person)(objectClass=user))(|(descript..., (&(objectCategory=Computer)(ms-MCS-AdmPwd=?)), (&(objectCategory=group)(name=Domain Admins)), (&(objectCategory=person)(lastLogon>=*, (&(objectCategory=person)(objectClass=user)(directReports...
host.os.type6eq 6
event.type5eq 5start
user.id4ne 4S-1-5-18
Description3eq 2, contains 1active directory editor, sharphound
Product3eq 2, contains 1sysinternals adexplorer, sharphound
Type3eq 3
event.category3eq 3process

Top indicator values (1525 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
process.Ext.api.nameeq
ldap_search
814
EventIDeq
4104
7269
EventIDeq
4688
5317
event.typeeq
start
51078
user.idne
S-1-5-18
436
CommandLinecontains
adinfo
34
CommandLinecontains
computers_pwdnotreqd
34
CommandLinecontains
dcmodes
34
CommandLinecontains
domainlist
34
CommandLinecontains
trustdmp
34
CommandLinecontains
oudmp
22
CommandLinecontains
-sc u:
22
CommandLinecontains
-subnets -f
22
CommandLinecontains
computer_pwdnotreqd
22
CommandLinecontains
computers_active
22
CommandLinecontains
domainncs
22
CommandLinecontains
dompol
22
CommandLinecontains
find-gpolocation
22
CommandLinecontains
fspdmp
22
CommandLinecontains
get-domaintrust
22
Imageends_with
\adexp.exe
33
Imageends_with
\adexplorer.exe
34
Imageends_with
\adexplorer64.exe
34
Imageends_with
\adexplorer64a.exe
34
OriginalFileNameeq
adexp
33
OriginalFileNameeq
nltestrk.exe
34
event.categoryeq
process
3142
event_countgt
0
33
process_nameeq
dsquery.exe
312
process_nameeq
nltest.exe
311

Exclusions (79 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagewildcard
?:\program files\azure advanced threat protection sensor\*\microsoft.tri.sensor.exe
7
Imagewildcard
?:\windows\adfs\microsoft.identityserver.servicehost.exe
7
Imagewildcard
?:\windows\adws\microsoft.activedirectory.webservices.exe
5
Imagewildcard
?:\windows\system32\lsass.exe
4
process.code_signature.trustedeq
true
3
user.idin
S-1-5-18
3
user.idin
S-1-5-19
3
user.idin
S-1-5-20
3
user.idin
s-1-5-18
2
user.idin
s-1-5-19
2
Computereq
%admin_workstation%
1
Computereq
%domain_controllers%
1
EventDatacontains
gc_service.exe
1
EventDatacontains
gc_worker.exe
1
Imagecontains
:\program files (x86)\
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 18 rules

Elastic 17 rules

Splunk 25 rules

Kusto 6 rules