Techniques › T1482
T1482 Domain Trust Discovery
discovery — Windows · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
17
Sigma rules tagged attack.t1482
2
KEV CVEs mapped here
<p>Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the
DSEnumerateDomainTrusts() Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.</p>KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2023-22952 | SugarCRM Multiple Products | secondary impact | Stale | 2023-02-02 |
| CVE-2022-41082 | Microsoft Exchange Server | secondary impact | Mapped | 2022-09-30 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0007 Detection of Domain Trust Discovery via API, Script, and CLI Enumeration v1.0
AN0016 WindowsAdversary uses nltest, PowerShell, or Win32/.NET API to enumerate domain trust relationships (via DSEnumerateDomainTrusts, GetAllTrustRelationships, or LDAP queries), followed by discovery or authentication staging.Tunable:
ParentImageTimeWindowUserContextAPI_Name
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1482
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-02 (modified 2025-12-10) · logsource: product=windows category=process_creation · 02030f2f-6199-49ec-b258-ea71b07e03dc
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: C.J. May
· 2022-08-09 (modified 2026-02-19) · logsource: product=windows category=file_event · 02773bed-83bf-469f-b7ff-e676e7d78bab
Detects default file names outputted by the BloodHound collection tool SharpHound
Author: Arnim Rupp (Nextron Systems), Thomas Patzke
· 2025-07-09 · logsource: product=windows category=file_event · 0a1255c5-d732-4b62-ac02-b5152d34fb83
Detects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
Author: Adeem Mawani
· 2021-06-22 (modified 2025-07-04) · logsource: product=windows service=ldap · 31d68132-4038-47c7-8f8e-635a39a7c174
Detects potential Active Directory enumeration via LDAP
Author: E.M. Anhaus, Tony Lambert, oscd.community, omkar72
· 2019-10-24 (modified 2023-02-02) · logsource: product=windows category=process_creation · 3bad990e-4848-4a78-9530-b427d854aac0
Detects execution of "dsquery.exe" for domain trust discovery
Author: Craig Young, oscd.community, Georg Lauenstein
· 2021-07-24 (modified 2023-12-15) · logsource: product=windows category=process_creation · 5cc90652-4cbd-4241-aa3b-4b462fa5a248
Detects nltest commands that can be used for information discovery
Author: frack113
· 2022-08-20 (modified 2023-02-13) · logsource: product=windows category=process_creation · 69ca006d-b9a9-47f5-80ff-ecd4d25d481a
Detects the use of TruffleSnout.exe an iterative AD discovery toolkit for offensive operators, situational awareness and targeted low noise enumeration.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-20 (modified 2025-12-10) · logsource: product=windows category=ps_module · 7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer
· 2017-03-05 (modified 2025-12-10) · logsource: product=windows category=ps_script · 89819aa4-bbd6-46bc-88ec-c7f7fe30efa6
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Arun Chauhan
· 2023-02-03 · logsource: product=windows category=process_creation · 903076ff-f442-475a-b667-4f246bcc203b
Detects nltest commands that can be used for information discovery
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-03-14 (modified 2025-07-09) · logsource: product=windows category=process_creation · 9212f354-7775-4e28-9c9f-8f0a4544e664
Detects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
Author: Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community
· 2021-02-02 (modified 2025-10-24) · logsource: product=windows category=process_creation · 9a132afa-654e-11eb-ae93-0242ac130002
Detects AdFind execution with common flags seen used during attacks
Author: frack113
· 2022-08-20 (modified 2023-09-18) · logsource: product=windows category=dns_query · a21bcd7e-38ec-49ad-b69a-9ea17e69509e
Detects DNS server discovery via LDAP query requests from uncommon applications
Author: frack113
· 2021-12-10 (modified 2023-02-14) · logsource: product=windows category=process_creation · b2317cfa-4a47-4ead-b3ff-297438c0bc2d
Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
Author: Florian Roth (Nextron Systems)
· 2022-08-21 (modified 2025-02-26) · logsource: product=windows category=process_creation · df55196f-f105-44d3-a675-e9dfb6cc2f2b
Detects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-03-14 (modified 2025-07-09) · logsource: product=windows category=process_creation · ef61af62-bc74-4f58-b49b-626448227652
Detects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database to a suspicious directory. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
Author: Florian Roth (Nextron Systems)
· 2019-12-20 (modified 2023-02-04) · logsource: product=windows category=process_creation · f376c8a7-a2d0-4ddc-aa0c-16c17236d962
Detects command line parameters used by Bloodhound and Sharphound hack tools