Domain or Tenant Policy Modification: Trust Modification T1484.002
Tactics: Defense Impairment, Privilege Escalation
Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privileges.Trust details, such as whether or not user identities are federated, allow authentication and authorization properties to apply between domains or tenants for the purpose of accessing shared resources. These trust objects may include accounts, credentials, and other authentication material applied to servers, tokens, and domains.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Security-Auditing | Event ID 5137 | A directory service object was created. |
Authoring guide
These 17 rules share fields, values, and exclusions.
Fields filtered most (23 distinct)
These fields appear most often in rule filters.
Top indicator values (54 distinct)
These values appear most often in rule predicates.
Exclusions (4 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 1 rule
Elastic 9 rules
- Attempt to Deactivate an Okta Network Zone
- AWS IAM OIDC Provider Created by Rare User
- AWS IAM SAML Provider Created
- AWS IAM SAML Provider Updated
- Domain Added to Google Workspace Trusted Domains
- Entra ID Domain Federation Configuration Change
- Entra ID Federated Identity Credential Issuer Modified
- M365 Exchange Federated Domain Created or Modified
- New Okta Identity Provider (IdP) Added by Admin
Splunk 3 rules
Kusto 2 rules
- PROD (TM018.1) - DOMAIN - Child Domain promoted within the Forest
- PROD (TM019.1) - TRUST - A new AD Trust has been established