Skip to content

Lateral Movement

Definition

Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access valuable data, or establish persistence. Tracing lateral movement requires correlating authentication logs, network flows, and endpoint telemetry across multiple systems.

Field
Incident response, network security
Occurs after
Initial compromise of one system
Common goals
Privilege escalation, data access, persistence
Detection sources
Authentication logs, network flows, endpoint telemetry

Common questions

Why is lateral movement hard to detect?+

Attackers often reuse legitimate administrative tools and valid credentials to move between systems, so the activity resembles normal admin behaviour rather than obvious malware. Detecting it depends on correlating patterns across multiple log sources rather than spotting a single suspicious event.

What techniques do attackers commonly use for lateral movement?+

Pass-the-hash and pass-the-ticket attacks reuse captured credentials without needing the plaintext password, while remote execution tools and exploited trust relationships between systems let an attacker pivot from a low-value entry point to systems holding the target data.

Related terms

Living-Off-the-Land (LotL)
An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
MITRE ATT&CK
A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
Anomaly-Based IDS
An intrusion detection system that models normal traffic behaviour and alerts when observed traffic deviates significantly from that baseline. Detects novel attacks...
Anti-Forensic Technique
Any action taken by an attacker to destroy, conceal, or alter evidence of their activity. Common examples include log clearing, timestomping, use...
Blast Radius
The full set of systems, accounts, and data that an attacker has accessed or could access given their current level of compromise....
Corroboration
The practice of confirming an observed attacker action by finding evidence of the same action in at least two independent data sources,...
Credential Dumping
Extraction of authentication credentials from operating system memory, the Windows SAM database, Active Directory, or credential stores. Tools such as Mimikatz target...
Credential Stuffing
An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across...
Cyber Kill Chain
A seven-phase linear model of an intrusion developed by Lockheed Martin in 2011. The phases are: Reconnaissance, Weaponisation, Delivery, Exploitation, Installation, Command...
Declaration Threshold
The criteria defined in an organisation's IR plan that a suspected event must meet before it is formally declared a confirmed incident,...
Dwell Time
The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
Five-Tuple
The five fields that uniquely identify a network flow: source IP address, source port, destination IP address, destination port, and transport protocol...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.