📅 Day 84 — Lateral Movement Techniques in Enterprise Networks
🔄 Topic
Understanding lateral movement and how attackers move from one compromised system to another inside a network.
🎯 Goal
Learn why lateral movement is a critical phase of enterprise intrusions and how defenders can detect it.
🛠 What I Did
Today I studied lateral movement.
Lateral movement is the process attackers use to move from one system to another after gaining initial access.
Initial access may give the attacker one machine.
Lateral movement helps them reach more valuable systems.
Examples:
- domain controllers
- file servers
- backup servers
- administrator workstations
- database servers
- cloud management systems
Common tools and methods include:
- PsExec
- WMI
- SMB
- Remote Desktop Protocol
- PowerShell Remoting
- stolen credentials
- Windows admin shares
Simplified attack flow:
compromised workstation
↓
credential discovery
↓
remote admin tool used
↓
second host accessed
↓
privileges expanded
↓
sensitive systems reached
🔗 Key Cybersecurity Connections
Lateral movement matters because attackers rarely stop at the first compromised device.
The first host may be low value.
The attacker wants to expand access.
For defenders, lateral movement often creates detectable evidence:
- remote logons
- new service creation
- SMB connections
- admin share usage
- remote command execution
- unusual process creation
- internal host-to-host traffic
- authentication events from strange sources
The challenge is that attackers often use legitimate administrative tools.
That means the question is not:
Is PsExec always malicious?
The better question is:
Is this user, from this host, using PsExec to this destination at this time normal?
🔍 Investigation Questions
- What was the first compromised host?
- Which account was used for lateral movement?
- Was the account privileged?
- Which destination systems were accessed?
- Was the access normal for that user?
- Was SMB, WMI, RDP, or PsExec involved?
- Were admin shares used?
- Was a new service created remotely?
- Did one host authenticate to many others?
- Did lateral movement happen after credential dumping?
- Is this normal admin activity or suspicious behavior?
🚨 Detection Opportunities
Possible detection ideas:
- one workstation connecting to many internal hosts
- non-admin workstation using administrative protocols
- remote service creation
- unusual RDP login between internal hosts
- WMI execution from rare source
- SMB admin share access
- privileged account used from abnormal workstation
- lateral movement shortly after suspicious PowerShell activity
- internal authentication spike
Example detection pattern:
source_host=WORKSTATION-22
destination_hosts=45
protocol=SMB
account=domain_admin
timeframe=10 minutes
suspicion=possible_lateral_movement
This is strong because normal users should not usually connect to many internal systems using privileged access.
🧭 MITRE ATT&CK Techniques
- T1021 — Remote Services
- T1021.002 — SMB/Windows Admin Shares
- T1047 — Windows Management Instrumentation
- T1569.002 — Service Execution
- T1078 — Valid Accounts
- T1550 — Use Alternate Authentication Material
🗺 Visual Investigation Diagram
Initial compromise
↓
Credentials obtained
↓
Remote access method used
↓
Internal host accessed
↓
Privileges expanded
↓
Critical system reached
⚠ Challenges
The main challenge is that lateral movement often looks like administration.
Administrators legitimately use tools like RDP, WMI, SMB, and PsExec.
Attackers use the same tools because they are effective and trusted.
So detection needs behavior and context.
Important context includes:
- source host
- destination host
- user account
- time of day
- frequency
- parent process
- command line
- historical baseline
📚 What I Learned
I learned that lateral movement is where attackers expand control.
It is also where defenders may have strong detection opportunities.
Initial access may be quiet.
Encryption may be too late.
Lateral movement sits in the middle, where good monitoring can make a major difference.
➡ Next Steps
- Study Windows logon types
- Learn event IDs related to remote logon
- Practice detecting PsExec-style behavior
- Review SMB admin share usage
- Build a fake lateral movement log lab
- Connect endpoint process logs with authentication logs
🧠 Reflection
This topic feels very important for real SOC work.
If I can detect lateral movement, I can help catch an intrusion before final impact.
That is exactly the kind of skill I need to build.
🧩 Lessons Learned
What worked
Thinking in terms of internal movement instead of only initial compromise.
What broke
Assuming internal traffic is automatically normal.
Why it broke
Attackers often operate inside the network using valid credentials and admin tools.
Fix / takeaway
Internal traffic still needs investigation, especially when privileged accounts and remote administration are involved.
📈 Skill Progression Context
Lateral movement detection is a core SOC and threat hunting skill.
It connects endpoint telemetry, authentication logs, network traffic, and identity analysis into one investigation.
😄 TL;DR
Initial access gets the attacker inside.
Lateral movement is them checking every room in the building.
