Lateral Movement

Lateral Movement

Laterale Bewegung

Lateral movement denotes the phase of an attack in which an intruder moves sideways through the network from the first compromised system in order to reach more valuable targets and higher privileges. The first hit is rarely the actual goal. Making this spread visible is one of the most important tasks of detection.

History & facts. After the first access (for instance via a phishing e-mail) typically follows the reconnaissance of the environment, the capture of further credentials and the advance to servers, databases or the directory service. Attackers often use legitimate administration tools and valid credentials (see Living off the Land) so as not to stand out — a technique listed in MITRE ATT&CK as its own tactic. Lateral movement in particular is the phase in which an initially small incident escalates into a company-wide catastrophe, for instance before a widespread ransomware deployment. Outlook & recommendation. Because attackers frequently use legitimate means here, pure signature detection is weak; what is needed is behaviour analysis, good network and identity telemetry and baits that an intruder inevitably touches (see Honeytoken, OpenCanary). Structurally, segmentation, least privilege and consistent MFA slow the spread. In the sense of Zero Trust: a single compromised machine must not automatically mean access to the rest of the network. The early detection of lateral movement often decides the extent of the damage.
Lateral Movement — Lateral Movement