One-Way Trust Bypass via TDO Hash Abuse (Kerberos/DCSync)

This rule detects potential attempts to abuse a Trusted Domain Object (TDO) to traverse a one-way Active Directory trust. It identifies suspicious activities such as Kerberos ticket requests (AS-REQ/TGS-REQ) targeting trust accounts (inter-realm indicators) or DCSync-style replication requests targeting the TDO object to extract domain secrets.