Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0007 — Detection of Domain Trust Discovery via API, Script, and CLI Enumeration
DET0007

Detection of Domain Trust Discovery via API, Script, and CLI Enumeration

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0016 Analytic 0016
Windows

Adversary uses nltest, PowerShell, or Win32/.NET API to enumerate domain trust relationships (via DSEnumerateDomainTrusts, GetAllTrustRelationships, or LDAP queries), followed by discovery or authentication staging.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=10 WinEventLog:PowerShell Get-ADTrust|GetAllTrustRelationships WinEventLog:Security EventCode=4662
[ParentImage] Tune based on expected script hosts or authorized administrators invoking trust enumeration.
[TimeWindow] Correlate enumeration + subsequent Kerberos activity or DC interaction within a bounded window.
[UserContext] Prioritize detection for non-admin or unexpected user accounts performing enumeration.
[API_Name] Flag uncommon or low-prevalence API calls like DSEnumerateDomainTrusts for inspection.

Detected Techniques

1

Details

MITRE ID
DET0007
STIX ID
x-mitre-detection-strategy--3414f3b8-17a2-438c-8bbc-a261a04da8bc
Analytics
1
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.