High severity Attack Technique

Lateral Movement

Once inside, the attacker pivots from the compromised host to neighbouring systems.

Overview

After the initial foothold, credentials are reused across the estate: RDP and SMB to workstations, WinRM and PsExec to servers, cloud API calls to adjacent subscriptions.\nBecause the traffic uses legitimate protocols and valid accounts, it blends into normal administration.\nNetwork segmentation and per-host credential isolation are what stop one laptop from becoming the domain.

Indicators of Compromise

Signals that suggest this is present on a system.

  • One account authenticating to many internal hosts
  • SMB or RDP sessions fanning out from a workstation
  • PsExec, WMI or WinRM execution on new hosts

Controls that stop it

  • Apply Least Privilege Everywhere

    Give accounts, processes, tokens and service principals the minimum permissions needed, for the minimum time. Review admin rights and service accounts on a schedule, remove standing privilege, and prefer short-lived credentials over long-lived keys. Deny by default so a missing check fails closed rather than open.

  • Segment the Network and Restrict Egress

    Do not let every host talk to every other host or to the whole internet. Segment by role, deny inbound administration from user networks, and filter outbound traffic so only the destinations a workload genuinely needs are reachable. Egress control is what stops an SSRF or an implant from reaching cloud metadata and command infrastructure.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used