Windows Process Creation: dsquery.exe TrustedDomain Discovery

Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.

FreeUnreviewedSigmamediumv1
title: "Windows Process Creation: dsquery.exe TrustedDomain Discovery"
id: 2c5ca846-5aee-4281-ae96-1e551383afd4
related:
  - id: b23fcb74-b1cb-4ff7-a31d-bfe2a7ba453b
    type: similar
  - id: 77815820-246c-47b8-9741-e0def3f57308
    type: obsolete
  - id: 3bad990e-4848-4a78-9530-b427d854aac0
    type: derived
status: test
description: This rule identifies execution of dsquery.exe when the command line includes the string trustedDomain, indicating discovery of domain trust relationships. Attackers commonly use built-in directory query tools to enumerate AD trust paths for further targeting and lateral movement planning. The detection relies on Windows process creation telemetry, including the executable name/path and command-line content.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1482/T1482.md
  - https://posts.specterops.io/an-introduction-to-manual-active-directory-querying-with-dsquery-and-ldapsearch-84943c13d7eb?gi=41b97a644843
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery.yml
author: E.M. Anhaus, Tony Lambert, oscd.community, omkar72, Huntrule Team
date: 2019-10-24
modified: 2023-02-02
tags:
  - attack.discovery
  - attack.t1482
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \dsquery.exe
    - OriginalFileName: dsquery.exe
  selection_cli:
    CommandLine|contains: trustedDomain
  condition: all of selection_*
falsepositives:
  - Legitimate use of the utilities by legitimate user for legitimate reason
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery/info.yml
simulation:
  - type: atomic-red-team
    name: Windows - Discover domain trusts with dsquery
    technique: T1482
    atomic_guid: 4700a710-c821-4e17-a3ec-9e4c81d6845f
license: DRL-1.1

What it detects

This rule identifies execution of dsquery.exe when the command line includes the string trustedDomain, indicating discovery of domain trust relationships. Attackers commonly use built-in directory query tools to enumerate AD trust paths for further targeting and lateral movement planning. The detection relies on Windows process creation telemetry, including the executable name/path and command-line content.

Known false positives

  • Legitimate use of the utilities by legitimate user for legitimate reason

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.