You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat: capture trust partner SID from trust enum to unblock child→parent forge (#311)
**Key Changes:**
- Added support for extracting and propagating the securityIdentifier
(domain SID) during domain trust enumeration and parsing
- Updated trust parsing logic to handle both canonical and
base64-encoded securityIdentifier formats
- Modified orchestrator state publishing to upsert domain SIDs from
trust data, ensuring correct automation on hardened DCs
- Expanded and improved test coverage to validate new SID extraction and
handling logic
**Added:**
- security_identifier field to TrustInfo struct, with appropriate serde
handling for optionality and defaulting - `ares-core/src/models/core.rs`
- Logic in trust parser to extract securityIdentifier from both
canonical text and base64-encoded LDAP outputs, including a decoder for
binary SIDs - `ares-tools/src/parsers/trust.rs`
- Tests for parsing, decoding, and correct state population of
securityIdentifier, including multiple edge cases and block boundaries -
`ares-tools/src/parsers/trust.rs`,
`ares-cli/src/orchestrator/state/publishing/entities.rs`
- Inline extraction and emission of canonical securityIdentifier in
impacket LDAP enumeration for pass-the-hash authentication -
`ares-tools/src/recon.rs`
**Changed:**
- Trust enumeration and parsing code paths to support and carry
securityIdentifier where present, ensuring downstream state and
automation logic can use the SID directly
- Orchestrator state publishing logic to upsert domain_sids from
trust-enum data, mirroring the post-SAMR lookup persistence path and
supporting automation on hardened 2019+ DCs -
`ares-cli/src/orchestrator/state/publishing/entities.rs`
- Test helpers and fixtures across several test modules to include
security_identifier in constructed TrustInfo instances where relevant
**Removed:**
- Redundant or now-unnecessary fallback logic and comments related to
SID acquisition via legacy mechanisms in favor of direct propagation
from trust enumeration
0 commit comments