Domain Trust Discovery via nltest.exe or dsquery.exe (T1482)
Detects the use of Windows utilities 'nltest.exe' and 'dsquery.exe' with specific command-line arguments to enumerate Active Directory domain trust relationships. This behavior is indicative of an attacker attempting to map the network environment to identify targets for lateral movement.
SentinelOne

