VLAN Segmentation
Definition
Moving a compromised device or subnet into a separate VLAN with restrictive access control lists, limiting lateral movement to other network segments without taking the host offline.
- Technique type
- Network containment control
- Action
- Moves a device or subnet into an isolated VLAN
- Combined with
- Restrictive access control lists
- Host state
- Stays online, not powered off
- Goal
- Blocks lateral movement to other segments
Common questions
Why keep the host powered on instead of disconnecting it?+
Short-term containment aims to stop an attacker's spread while preserving volatile evidence such as running processes and memory contents, and in some cases while keeping a business service partially available. Isolating the network path achieves containment without losing that evidence.
Can a sufficiently privileged attacker escape VLAN segmentation?+
Yes, if the attacker has already compromised the switch, router, or a device with access to multiple VLANs, or exploits a misconfigured ACL. Responders verify the segmentation is enforced correctly rather than assuming a VLAN move alone is airtight.
Related terms
- Attacker-Alerting Risk
- The risk that a containment action signals to the attacker that they have been detected, potentially triggering destructive countermeasures on systems they...
- Network Isolation
- Disconnecting a compromised host from all network interfaces while leaving it powered on. Preserves volatile memory contents but removes the attacker's communication...
- Short-Term Containment
- Immediate actions taken after incident confirmation to stop an attack from spreading, without waiting for full scope analysis. Distinguished from long-term containment,...
- Traffic Blocking
- Adding firewall rules, null routes, or DNS sinkholes to deny communication between attacker-controlled infrastructure and the victim network. Effective against external command-and-control...
- Volatile Evidence
- Data that exists only while a system is running: active processes, logged-in sessions, network socket state, decryption keys in memory, and command...