Domain Trust Discovery via nltest or PowerShell
This rule detects the use of native Windows utilities such as nltest.exe, netdom.exe, and PowerShell to enumerate Active Directory domain trust relationships. Attackers commonly perform this discovery to map out target environments, identify lateral movement opportunities, or plan further exploitation in multi-domain or forest environments.
Microsoft Sentinel (KQL)

