daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

trust-relationship.md (2612B)


      1 ---
      2 title: "Trust - Relationship"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/trust-relationship.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/trust-relationship.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Trust - Relationship
     12 
     13 - One-way
     14     - Domain B trusts A
     15     - Users in Domain A can access resources in Domain B
     16     - Users in Domain B cannot access resources in Domain A
     17 - Two-way
     18     - Domain A trusts Domain B
     19     - Domain B trusts Domain A
     20     - Authentication requests can be passed between the two domains in both directions
     21 
     22 ## Enumerate trusts between domains
     23 
     24 - Native `nltest`
     25 
     26   ```powershell
     27   nltest /trusted_domains
     28   ```
     29 
     30 - PowerShell `GetAllTrustRelationships`
     31 
     32   ```powershell
     33   ([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()
     34 
     35   SourceName          TargetName                    TrustType      TrustDirection
     36   ----------          ----------                    ---------      --------------
     37   domainA.local      domainB.local                  TreeRoot       Bidirectional
     38   ```
     39 
     40 - netexec module `enum_trusts`
     41 
     42   ```powershell
     43   nxc ldap <ip> -u <user> -p <pass> -M enum_trusts 
     44   ```
     45 
     46 ## Exploit trusts between domains
     47 
     48 :warning: Require a Domain-Admin level access to the current domain.
     49 
     50 | Source   | Target   | Technique to use                                          | Trust relationship                     |
     51 | -------- | -------- | --------------------------------------------------------- | -------------------------------------- |
     52 | Root     | Child    | Golden Ticket + Enterprise Admin group (Mimikatz /groups) | Inter Realm (2-way)                    |
     53 | Child    | Child    | SID History exploitation (Mimikatz /sids)                 | Inter Realm Parent-Child (2-way)       |
     54 | Child    | Root     | SID History exploitation (Mimikatz /sids)                 | Inter Realm Tree-Root (2-way)          |
     55 | Forest A | Forest B | PrinterBug + Unconstrained delegation ?                   | Inter Realm Forest or External (2-way) |
     56 
     57 ## References
     58 
     59 - [External Trusts Are Evil - 14 March 2023 - Charlie Clark (@exploitph)](https://exploit.ph/external-trusts-are-evil.html)
     60 - [Carlos Garcia - Rooted2019 - Pentesting Active Directory Forests public.pdf](https://www.dropbox.com/s/ilzjtlo0vbyu1u0/Carlos%20Garcia%20-%20Rooted2019%20-%20Pentesting%20Active%20Directory%20Forests%20public.pdf?dl=0)
     61 - [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)