What is Lateral Movement?

You lock your front door to keep people out. But when an intruder is already inside, the front door isn’t the problem anymore.

After cybercriminals gain initial access, they start looking for paths to systems that give them more control in your environment. That’s lateral movement, and it looks a lot like normal IT work.

An attacker might steal credentials from a device they already control, then use legitimate remote management tools and protocols, like RDP, WinRM, or SMB, to sign in elsewhere. From there, they can run commands with PsExec, WMI, or PowerShell, just like your IT team does for admin tasks.

The first computer an attacker reaches is rarely their end goal. They’re likely trying to reach a domain controller, access a backup server, find sensitive data, or get a foothold to deploy ransomware across the network.

Watch a Huntress SOC analyst explain how lateral movement works and the signals that help uncover it.

Share

[PH] Learn More About Phishing

[PH] Huntress delivers everything you want from a security tool, all designed with the unique needs of outsourced IT and security teams in mind.
[PH] Phishing attempts can show up as messages from your bank, your boss, your utility providers, or even the government. One click from one user can compromise an entire network and inadvertently let hackers deploy ransomware, steal information, or worse.
[PH] The median time it takes for a user to click a link and enter information is less than 60 seconds. With a turnaround time that quick, it's no wonder phishing is one of the preferred methods used by hackers. (2024 Verizon Data Breach Report)