logo

Untrustworthy Trust Builders: Account Operators Replicating Trust Attack (AORTA)

ID: 587ab78c-dc7d-53b0-b7f5-541b6561c2e3

STIX ID: report--587ab78c-dc7d-53b0-b7f5-541b6561c2e3

Feed Name: SpecterOps Blog

Threat Score
72/100

Date Published: 2025-06-25

Date Updated: 2026-04-30

Author: Jonas Bülow Knudsen

...
...

This report documents AORTA, an Active Directory privilege-escalation technique where users with Create-Inbound-Forest-Trust rights (Incoming Forest Trust Builders), combined with DNS control (DnsAdmins), can create inbound forest trusts with TGT delegation enabled; by coercing a DC to authenticate to an attacker-controlled host with unconstrained delegation, the attacker captures the DC's TGT and performs DCSync to extract domain credentials. The author details discovery, RPC-level implementation, a PowerShell POC and a robust tool (Trustify), demonstrates the full attack chain in lab, provides detection (Event ID 4706 bitmask) and mitigation recommendations (treat groups as Tier Zero, mark DCs NOT_DELEGATED or use Protected Users), and summarizes Microsoft’s response (documentation update only).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.