Domain Trust Enumeration
Enumerate Domain Trusts (PowerView)
Show Existing Trusts
Get-DomaintrustShow Trust Mapping
Get-DomainTrustMappingShow Users in the Child Domain
Get-DomainUser -Domain LOGISTICS.INLANEFREIGHT.LOCAL | select SamAccountNameAttacking Domain Trusts - Child -> Parent (Windows)
1 Obtaining KRBTGT NT Hash
2 Obtaining SID Child Domain
3 Name Target User
4 FQDN Child Domain
5 SID Enterprise Admins Group
6 Putting It All Together
7 Confirm Ticket
8 DCsync
Attacking Domain Trusts - Child -> Parent (Linux)
1 Get KRBTGT NT Hash
2 Get SID Child Domain
3 Name Target User
4 Get SID Enterprise Admins
5 Putting it all Together
6 Export ccache
7 Get Shell
Automatic Way
Attacking Domain Trust - Cross-Forest (Windows)
Cross-Forest Kerberoasting
Admin Password Reuse & Group Membership
SID History Abuse
Attacking Domain Trusts - Cross-Forest Trust Abuse (Linux)
Cross-Forest Kerberosting
Last updated