Skip to content

AD Architecture

Active Directory (AD) is a hierarchical directory service that organizes network resources into a structured, scalable architecture. This section provides an overview of its core components: domains, forests, and trust relationships, which form the foundation for Kerberos-based authentication and privilege escalation in Red Team operations.


Domains: Logical Groupings of Resources

A domain is a logical group of network resources (computers, users, devices) managed under a shared directory database. Each domain is governed by one or more domain controllers (DCs), which host the Active Directory Domain Services (AD DS) role.

  • Key characteristics:
  • Schema: Defines object classes and attributes for all objects in the domain.
    Partitioning: The directory database is split into partitions (e.g., Configuration, Schema, Domain Partition) for scalability.
  • Kerberos Authentication: DCs act as Key Distribution Centers (KDCs) for Kerberos ticket issuance.

Example: A single domain might represent a department within an organization, with users and resources isolated from other domains.

Command:

# Query domain information via PowerShell  
Get-ADDomain


Forests: Collections of Domains

A forest is a collection of one or more domains linked by trust relationships. Forests provide a security boundary for cross-domain communication and resource sharing.

  • Key characteristics:
  • Root Domain: The first domain created in the forest (e.g., example.com).
  • Trust Relationships: Domains within the same forest can trust each other, enabling seamless authentication.
  • Schema and Configuration Partitions: These are replicated across all domains in the forest.

Example: A multi-domain forest might consist of finance.example.com, hr.example.com, and it.example.com, all sharing a common schema and configuration.

Command:

# List domains in the current forest  
Get-ADForest | Select-Object Domains


Trust Relationships: Enabling Cross-Domain Communication

Trust relationships define how domains interact, allowing users and resources to access objects across domains. Trusts can be unidirectional or bidirectional, and transitive or non-transitive.

  • Common trust types:
  • Parent-Child Trust: Unidirectional, transitive (e.g., child.example.com trusts example.com).
  • Tree-Down Trust: Bidirectional, non-transitive (e.g., between sibling domains in the same tree).
  • Forest-Wide Trust: Bidirectional, transitive (e.g., between domains in different trees within the same forest).

  • Kerberos Implications: Trusts enable cross-domain Kerberos ticket validation, but misconfigured trusts can lead to privilege escalation (e.g., through pass-the-ticket or golden ticket attacks).

Example: A malicious actor might exploit a forest-wide trust to escalate privileges across domains.

Command:

# Check existing trust relationships  
Get-ADTrust


Key takeaways

  • Domains are the building blocks of AD, managed by DCs and governed by Kerberos.
  • Forests aggregate domains into a security boundary, sharing schema and configuration.
  • Trust relationships enable cross-domain communication but introduce attack surfaces for exploitation.
  • Understanding these layers is critical for analyzing and mitigating Kerberos-based attacks in AD environments.