Lateral Movement
Lateral movement is the phase of an intrusion in which an attacker, having compromised one machine, moves to others inside the same network to reach the data or systems that were the actual target. It relies on stolen credentials, remote administration protocols and trust between hosts rather than on new exploits.
The first machine an attacker lands on is almost never the one they want. A phished laptop is a foothold; the file server, the domain controller and the backup system are the targets, and the path from one to the others is lateral movement. It uses what the network already allows: RDP, SMB, WMI, PowerShell remoting, SSH, and credentials harvested from memory or reused across accounts.
Because it uses legitimate protocols and often legitimate accounts, lateral movement hides in normal administration traffic. The tells are contextual: a workstation authenticating to twenty servers in a minute, an account logging in from a host it has never used, a service account opening an interactive session.
Threat intelligence contributes at the edges of the movement. The tooling an attacker stages on each new host reaches back to C2 infrastructure, and the credentials used were often obtained by an infostealer whose logs are traded. Knowing those indicators turns an ambiguous internal event into a confirmed intrusion.
Example
A single workstation begins authenticating to fifteen servers over SMB within a minute, using a domain administrator account that normally logs in from one jump host. Minutes later a new process on three of those servers connects to an address listed as a C2 server. The internal pattern was suspicious; the external indicator made it certain.
In isMalicious
isMalicious does not see inside a network, but it identifies what leaves it: the C2 addresses the staged tooling contacts and the hosting patterns that mark them. A lookup on the destination of an unexpected outbound connection is often the fastest confirmation that internal movement is hostile.
Frequently Asked Questions
What is Lateral Movement?
Lateral movement is the phase of an intrusion in which an attacker, having compromised one machine, moves to others inside the same network to reach the data or systems that were the actual target. It relies on stolen credentials, remote administration protocols and trust between hosts rather than on new exploits.
How is Lateral Movement related to C2 (Command and Control)?
Lateral Movement and C2 (Command and Control) are both key concepts in threat intelligence. A Command and Control server is infrastructure used by attackers to remotely control compromised hosts (a botnet) and deliver instructions, exfiltrate data, or push malware updates. Blocking C2 communications is one of the most effective ways to disrupt an active attack.
Related Terms
C2 (Command and Control)
A Command and Control server is infrastructure used by attackers to remotely control compromised hosts (a botnet) and deliver instructions, exfiltrate data, or push malware updates. Blocking C2 communications is one of the most effective ways to disrupt an active attack.
Incident Response
Incident response (IR) is the structured process of detecting, containing, eradicating, and recovering from a security incident, then conducting a post-incident review to prevent recurrence. The SANS PICERL model defines six phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
TTP (Tactics, Techniques, and Procedures)
TTPs describe the behavior of threat actors: the high-level goals they pursue (tactics), the specific methods they use to achieve those goals (techniques), and the detailed, repeatable actions that implement those methods (procedures). The MITRE ATT&CK framework catalogues TTPs used by real adversaries.
MITRE ATT&CK
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. It is used as a foundation for threat detection, red team exercises, and gap analysis in security programs. The framework covers Enterprise, Mobile, and ICS environments.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.