Skip to main content
Threat IntelligenceUpdated September 3, 2026

Lateral Movement

Lateral movement is the phase of an intrusion in which an attacker, having compromised one machine, moves to others inside the same network to reach the data or systems that were the actual target. It relies on stolen credentials, remote administration protocols and trust between hosts rather than on new exploits.

The first machine an attacker lands on is almost never the one they want. A phished laptop is a foothold; the file server, the domain controller and the backup system are the targets, and the path from one to the others is lateral movement. It uses what the network already allows: RDP, SMB, WMI, PowerShell remoting, SSH, and credentials harvested from memory or reused across accounts.

Because it uses legitimate protocols and often legitimate accounts, lateral movement hides in normal administration traffic. The tells are contextual: a workstation authenticating to twenty servers in a minute, an account logging in from a host it has never used, a service account opening an interactive session.

Threat intelligence contributes at the edges of the movement. The tooling an attacker stages on each new host reaches back to C2 infrastructure, and the credentials used were often obtained by an infostealer whose logs are traded. Knowing those indicators turns an ambiguous internal event into a confirmed intrusion.

Example

A single workstation begins authenticating to fifteen servers over SMB within a minute, using a domain administrator account that normally logs in from one jump host. Minutes later a new process on three of those servers connects to an address listed as a C2 server. The internal pattern was suspicious; the external indicator made it certain.

In isMalicious

isMalicious does not see inside a network, but it identifies what leaves it: the C2 addresses the staged tooling contacts and the hosting patterns that mark them. A lookup on the destination of an unexpected outbound connection is often the fastest confirmation that internal movement is hostile.

Frequently Asked Questions

What is Lateral Movement?

Lateral movement is the phase of an intrusion in which an attacker, having compromised one machine, moves to others inside the same network to reach the data or systems that were the actual target. It relies on stolen credentials, remote administration protocols and trust between hosts rather than on new exploits.

How is Lateral Movement related to C2 (Command and Control)?

Lateral Movement and C2 (Command and Control) are both key concepts in threat intelligence. A Command and Control server is infrastructure used by attackers to remotely control compromised hosts (a botnet) and deliver instructions, exfiltrate data, or push malware updates. Blocking C2 communications is one of the most effective ways to disrupt an active attack.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary