AD Architecture
Active Directory (AD) is a hierarchical directory service that organizes network resources into a structured, scalable architecture. This section provides an overview of its core components: domains, forests, and trust relationships, which form the foundation for Kerberos-based authentication and privilege escalation in Red Team operations.
Domains: Logical Groupings of Resources¶
A domain is a logical group of network resources (computers, users, devices) managed under a shared directory database. Each domain is governed by one or more domain controllers (DCs), which host the Active Directory Domain Services (AD DS) role.
- Key characteristics:
- Schema: Defines object classes and attributes for all objects in the domain.
Partitioning: The directory database is split into partitions (e.g., Configuration, Schema, Domain Partition) for scalability. - Kerberos Authentication: DCs act as Key Distribution Centers (KDCs) for Kerberos ticket issuance.
Example: A single domain might represent a department within an organization, with users and resources isolated from other domains.
Command:
Forests: Collections of Domains¶
A forest is a collection of one or more domains linked by trust relationships. Forests provide a security boundary for cross-domain communication and resource sharing.
- Key characteristics:
- Root Domain: The first domain created in the forest (e.g.,
example.com). - Trust Relationships: Domains within the same forest can trust each other, enabling seamless authentication.
- Schema and Configuration Partitions: These are replicated across all domains in the forest.
Example: A multi-domain forest might consist of finance.example.com, hr.example.com, and it.example.com, all sharing a common schema and configuration.
Command:
Trust Relationships: Enabling Cross-Domain Communication¶
Trust relationships define how domains interact, allowing users and resources to access objects across domains. Trusts can be unidirectional or bidirectional, and transitive or non-transitive.
- Common trust types:
- Parent-Child Trust: Unidirectional, transitive (e.g.,
child.example.comtrustsexample.com). - Tree-Down Trust: Bidirectional, non-transitive (e.g., between sibling domains in the same tree).
-
Forest-Wide Trust: Bidirectional, transitive (e.g., between domains in different trees within the same forest).
-
Kerberos Implications: Trusts enable cross-domain Kerberos ticket validation, but misconfigured trusts can lead to privilege escalation (e.g., through pass-the-ticket or golden ticket attacks).
Example: A malicious actor might exploit a forest-wide trust to escalate privileges across domains.
Command:
Key takeaways¶
- Domains are the building blocks of AD, managed by DCs and governed by Kerberos.
- Forests aggregate domains into a security boundary, sharing schema and configuration.
- Trust relationships enable cross-domain communication but introduce attack surfaces for exploitation.
- Understanding these layers is critical for analyzing and mitigating Kerberos-based attacks in AD environments.