Threat

Lateral Movement

Lateral Movement describes how attackers move from system to system and escalate privileges after initial access.

Lateral movement refers to an attacker moving from one compromised system to others on the network. The goal is to gain access to more valuable permissions and data.

How it works

After initial access, an attacker is usually on a standard workstation. From there, they search for credentials, accessible servers, and administrative accounts. They often use legitimate tools like RDP, SMB, PowerShell Remoting or remote maintenance tools. Each step brings them closer to a target, such as the domain controller or backup servers.

For example, an attacker compromises a laptop in the marketing department. They extract the cached credentials of an IT support staff member who recently logged in there. Using this account, the attacker connects to a server via RDP. The SOC detects the unusual connection from the marketing laptop to the server and locks the account.

What to look out for

  • Administrators should not use privileged accounts on standard workstations.
  • Segment the network so workstations cannot reach every server.
  • Restrict RDP and other remote access to specific admin systems.
  • Monitor connections between workstations. They are rare in normal operation.
  • Use decoy accounts to detect attackers searching for credentials.

Why it matters

A phase of network movement almost always precedes the actual damage. This is the best time to stop an attack. The attacker is already active but has not yet reached their goal.

Detection

Lateral movement is difficult to detect because it uses legitimate tools. Combining signals from EDR, identity logs, and NDR is helpful. Unusual login paths are often the clearest indicator of an attack.

Typical mistakes

A common mistake is using the same local admin password on many devices. A single discovery can compromise the entire network. Solutions such as Windows LAPS prevent this issue.

How we implement it

We correlate signals from EDR, identity, and NDR to detect network movements early. We then lock affected accounts and devices according to our mandate.

How ANOMAL implements this