Domain or Tenant Policy Modification: Trust Modification T1484.002

Tactics: Defense Impairment, Privilege Escalation

Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privileges.Trust details, such as whether or not user identities are federated, allow authentication and authorization properties to apply between domains or tenants for the purpose of accessing shared resources. These trust objects may include accounts, credentials, and other authentication material applied to servers, tokens, and domains.

Events covered

1 catalog event is tagged with this technique by at least one rule.

Authoring guide

These 17 rules share fields, values, and exclusions.

Fields filtered most (23 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType10eq 8, in 2UPDATE, add-federateddomain, add_trusted_domains, createopenidconnectprovider, createsamlprovider
data_stream.dataset8eq 8aws.cloudtrail, okta.system, azure.auditlogs, google_workspace.admin, o365.audit
event.outcome5eq 5success
Provider_Name4eq 4iam.amazonaws.com, exchange
sourcetype3eq 3azure:monitor:aad, o365:management:activity
EventData2contains 2"objectclass">crossref, "objectclass">trusteddomain, cn=partitions,cn=configuration, cn=system
EventID2eq 25137
Operation2contains 1, in 1add, add a partner to cross-tenant access setting., delete partner specific cross-tenant access setting., domain, new
event.category2eq 2ADMINISTRATOR_MANAGEMENT, web
operationName2eq 2add unverified domain, set domain authentication
properties.result2eq 2success
Esql.external_idp_new_issuer1is_not_null 1
Esql.external_idp_old_issuer1is_not_null 1, ne 1esql.external_idp_new_issuer
Workload1eq 1azureactivedirectory
action1in 1CreateSAMLIdentityProvider, DeleteSAMLIdentityProvider, ModifySAMLIdentityProviderGroupMappings

Top indicator values (54 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
5375
Provider_Nameeq
iam.amazonaws.com
332
data_stream.dataseteq
aws.cloudtrail
3173
data_stream.dataseteq
okta.system
248
EventIDeq
5137
214
properties.resulteq
success
26
sourcetypeeq
azure:monitor:aad
247
Esql.external_idp_old_issuerne
esql.external_idp_new_issuer
1
EventDatacontains
"objectclass">crossref
1
EventDatacontains
"objectclass">trusteddomain
1
EventDatacontains
cn=partitions,cn=configuration
1
EventDatacontains
cn=system
1
EventTypeeq
UPDATE
13
EventTypeeq
add_trusted_domains
1
EventTypeeq
createopenidconnectprovider
1
EventTypeeq
createsamlprovider
1
EventTypeeq
system.idp.lifecycle.create
1
EventTypeeq
update application
1
EventTypeeq
updatesamlprovider
1
EventTypeeq
zone.deactivate
1
EventTypein
add-federateddomain
1
EventTypein
new-accepteddomain
1
EventTypein
remove-accepteddomain
1
EventTypein
remove-federateddomain
1
EventTypein
set domain authentication
1
EventTypein
set federation settings on domain
1
EventTypein
set-accepteddomain
1
EventTypein
set-msoldomainfederationsettings
1
Operationcontains
add
1
Operationcontains
domain
12

Exclusions (4 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
aws::sourceIPAddresseq
sso.amazonaws.com
1
aws::userAgentcontains
eksctl
1
aws::userAgentcontains
terraform
1
aws::userAgenteq
sso.amazonaws.com
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 1 rule

Elastic 9 rules

Splunk 3 rules

Kusto 2 rules

Panther 2 rules