Windows Process Creation: dsquery.exe TrustedDomain Discovery
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
FreeUnreviewedSigmamediumv1
windows-process-creation-dsquery-exe-trusteddomain-discovery-3bad990e
title: "Windows Process Creation: dsquery.exe TrustedDomain Discovery"
id: 2c5ca846-5aee-4281-ae96-1e551383afd4
related:
- id: b23fcb74-b1cb-4ff7-a31d-bfe2a7ba453b
type: similar
- id: 77815820-246c-47b8-9741-e0def3f57308
type: obsolete
- id: 3bad990e-4848-4a78-9530-b427d854aac0
type: derived
status: test
description: This rule identifies execution of dsquery.exe when the command line includes the string trustedDomain, indicating discovery of domain trust relationships. Attackers commonly use built-in directory query tools to enumerate AD trust paths for further targeting and lateral movement planning. The detection relies on Windows process creation telemetry, including the executable name/path and command-line content.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1482/T1482.md
- https://posts.specterops.io/an-introduction-to-manual-active-directory-querying-with-dsquery-and-ldapsearch-84943c13d7eb?gi=41b97a644843
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery.yml
author: E.M. Anhaus, Tony Lambert, oscd.community, omkar72, Huntrule Team
date: 2019-10-24
modified: 2023-02-02
tags:
- attack.discovery
- attack.t1482
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \dsquery.exe
- OriginalFileName: dsquery.exe
selection_cli:
CommandLine|contains: trustedDomain
condition: all of selection_*
falsepositives:
- Legitimate use of the utilities by legitimate user for legitimate reason
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery/info.yml
simulation:
- type: atomic-red-team
name: Windows - Discover domain trusts with dsquery
technique: T1482
atomic_guid: 4700a710-c821-4e17-a3ec-9e4c81d6845f
license: DRL-1.1
What it detects
This rule identifies execution of dsquery.exe when the command line includes the string trustedDomain, indicating discovery of domain trust relationships. Attackers commonly use built-in directory query tools to enumerate AD trust paths for further targeting and lateral movement planning. The detection relies on Windows process creation telemetry, including the executable name/path and command-line content.
Known false positives
- Legitimate use of the utilities by legitimate user for legitimate reason
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.