🟢SID Abuse
Cross-Domain Attacks: Forest Root and SID Abuse
Key Steps in the Attack
Risks and Implications
Mitigation Strategies
Practice
Invoke-Mimikatz
1. We require the trust key of inter-forest trust
2. Forge the inter-forest TGT
3. Request a TGS
4. Inject and use the TGS
Rubeus
1. Create ticket and add it into the memory using asktgs
PowerShell
1. Access the euvendor-net machine using PSRemoting
Extras
To use the DCSync feature for getting krbtg hash execute the below command with DC privileges
Get the ForeignSecurityPrincipal
Last updated