Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
- Product
- windows
- Category
- process_creation
- Author
- E.M. Anhaus, Tony Lambert, oscd.community, omkar72 (SigmaHQ), DRL 1.1
- Published
- 2019-10-24
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows executions of dsquery.exe where the command line includes the parameter string 'trustedDomain'. Attackers can use this information discovery behavior to enumerate domain trust relationships and map Active Directory connectivity. Telemetry relies on process creation events that include the executed image name/path and the full command line arguments.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1482/T1482.md
- posts.specterops.iohttps://posts.specterops.io/an-introduction-to-manual-active-directory-querying-with-dsquery-and-ldapsearch-84943c13d7eb?gi=41b97a644843
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
id: 2c5ca846-5aee-4281-ae96-1e551383afd4
related:
- id: b23fcb74-b1cb-4ff7-a31d-bfe2a7ba453b
type: similar
- id: 77815820-246c-47b8-9741-e0def3f57308
type: obsolete
- id: 3bad990e-4848-4a78-9530-b427d854aac0
type: derived
status: test
description: This rule identifies Windows executions of dsquery.exe where the command line includes the parameter string 'trustedDomain'. Attackers can use this information discovery behavior to enumerate domain trust relationships and map Active Directory connectivity. Telemetry relies on process creation events that include the executed image name/path and the full command line arguments.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1482/T1482.md
- https://posts.specterops.io/an-introduction-to-manual-active-directory-querying-with-dsquery-and-ldapsearch-84943c13d7eb?gi=41b97a644843
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery.yml
author: E.M. Anhaus, Tony Lambert, oscd.community, omkar72, Huntrule Team
date: 2019-10-24
modified: 2023-02-02
tags:
- attack.discovery
- attack.t1482
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \dsquery.exe
- OriginalFileName: dsquery.exe
selection_cli:
CommandLine|contains: trustedDomain
condition: all of selection_*
falsepositives:
- Legitimate use of the utilities by legitimate user for legitimate reason
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery/info.yml
simulation:
- type: atomic-red-team
name: Windows - Discover domain trusts with dsquery
technique: T1482
atomic_guid: 4700a710-c821-4e17-a3ec-9e4c81d6845f
license: DRL-1.1