Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound
ID: e306ff58-7650-5fa9-8f36-7cd1a2c853b8
STIX ID: report--e306ff58-7650-5fa9-8f36-7cd1a2c853b8
Feed Name: SpecterOps Blog
This post introduces BloodHound v7.4–v7.5 enhancements for mapping Active Directory trust attack paths: replacing the TrustedBy edge with SameForestTrust (traversable) and CrossForestTrust (non-traversable), adding traversable edges for abusable cross-forest configurations (AbuseTGTDelegation and SpoofSIDHistory), capturing trustAttributes from both sides to correctly model SID filtering and TGT delegation, expanding special identity modeling (Authenticated Users/Everyone propagation and a new ClaimSpecialIdentity edge), and adding HasTrustKeys to represent the trust account attack. It clarifies when and how SID history spoofing and TGT delegation can be abused across trusts, highlights limitations like selective authentication and transitivity, and provides guidance to audit trusts and understand forest-wide security boundaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
