1200KM / simulation
T1482 Domain Trust Discovery — Attack Simulation
Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help…
Technique description
Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Adfind - Enumerate Active Directory Trusts
Procedure 15fe436d-e771-4ff3-b655-2dca9ba52834; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Windows - Discover domain trusts with nltest
Procedure 2e22641d-0498-48d2-b9ff-c71e496ccdbe; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Windows - Discover domain trusts with dsquery
Procedure 4700a710-c821-4e17-a3ec-9e4c81d6845f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Get-ForestTrust with PowerView
Procedure 58ed10e8-0738-4651-8408-3a3e9a526279; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Powershell enumerate domains and forests
Procedure c58fbc62-8a62-489e-8f2d-3565d7d96f30; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Adfind - Enumerate Active Directory OUs
Procedure d1c73b96-ab87-4031-bad8-0e1b3b8bf3ec; elevation not declared required; cleanup not declared. Not executed or individually validated.
- TruffleSnout - Listing AD Infrastructure
Procedure ea1b4f2d-5b82-4006-b64f-f2845608a3bf; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Get-DomainTrust with PowerView
Procedure f974894c-5991-4b19-aaf5-7cc2fe298c5d; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.