AD-TRUST-05 - Trust configuration details should be retrievable
Overviewโ
Comprehensive trust documentation is essential for security operations:
- Security Audits: Auditors require detailed trust configuration information
- Incident Response: Understanding trust relationships helps during security incidents
- Change Management: Tracking trust configurations supports change control processes
- Risk Assessment: Detailed trust information enables proper risk evaluation
- Compliance: Many frameworks require documentation of trust relationships
Trust details reveal critical security properties including:
- Direction: Who can access whose resources
- Type: External vs Forest trust (different security models)
- SID Filtering: Whether the trust has strong SID filtering
- Selective Authentication: Whether authentication is restricted
- Trust Classification: Derived
IsForest,IsExternal, andSidFilteringWeakproperties
Control Typeโ
Operational
Security Recommendationโ
Configuration Best Practices:
- Use Forest Trusts: Prefer forest trusts over external trusts for better security
- Enable SID Filtering: Always enable SID filtering on external trusts
- Selective Authentication: Use selective authentication when possible
- Inbound Only: Prefer inbound trusts over bidirectional when possible
- Document Everything: Maintain detailed documentation of each trust's purpose
Trust Properties to Monitor:
Quarantined: Should be$truefor external trusts (SID filtering enabled)SidFilteringWeak: Should be$falsefor both external and forest trustsSelectiveAuthentication: Consider enabling for sensitive environmentsDirection: Bidirectional trusts have higher riskIsForest/IsExternal: Helps identify which SID filtering rules apply
How the Test Worksโ
This test retrieves all trust properties from LDAP and derives display values:
- Quarantined: Derived from
trustAttributesbit0x4(QUARANTINED_DOMAIN) - Selective Authentication: Derived from
trustAttributesbit0x10(CROSS_ORGANIZATION) - Intra-Forest: Derived from
trustAttributesbit0x20(WITHIN_FOREST) - IsForest: Derived from
trustAttributesbit0x8(FOREST_TRANSITIVE) - IsExternal: Derived from
trustTypein1,2and absence ofFOREST_TRANSITIVE/WITHIN_FOREST - SidFilteringWeak: External trusts weak when
QUARANTINED_DOMAINnot set; forest trusts weak whenTREAT_AS_EXTERNAL(0x40) is set - Trust Type: Mapped from numeric
trustType(1=External Downlevel, 2=Domain Uplevel, 3=MIT Kerberos, 4=DCE) - Direction: Mapped from numeric
trustDirection(1=Inbound, 2=Outbound, 3=Bidirectional)
Related Testsโ
Test-MtAdTrustTotalCount- Overall trust countTest-MtAdTrustInterForestCount- External trust identificationTest-MtAdTrustQuarantinedCount- SID filtering statusTest-MtAdTrustStaleCount- Trust validation status
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-TRUST-05 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Trust |
| PowerShell test | Test-MtAdTrustDetails |
| Tags | AD, AD-TRUST-05, AD.Trust |
Sourceโ
- Pester test:
tests/ad/trust/Test-MtAdTrustDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/trust/Test-MtAdTrustDetails.ps1

