Lateral Movement
After establishing a foothold, adversaries move laterally to reach high-value targets — domain controllers, backup systems, and sensitive data stores. ManySignal correlates authentication, network, and process events across systems to detect lateral movement in real time.
Coverage
- Techniques covered
- 9
- Detection rules
- 44
- PtH/PtT detections
- 12
Threat context
How adversaries move through your environment
Lateral movement is where breaches grow from individual incidents into organisation-wide compromises. Pass-the-Hash and Pass-the-Ticket allow attackers to authenticate to network shares, remote hosts, and services without knowing cleartext passwords. In Active Directory environments, a single NTLM hash obtained from LSASS can provide access to dozens of systems that share local administrator passwords.
Cloud lateral movement is structurally different: an attacker with one set of cloud credentials can immediately access many services simultaneously. ManySignal's entity graph models normal access patterns per identity and generates alerts when a principal accesses resources outside their established pattern — detecting lateral movement as it begins rather than after it is complete.
Techniques
Lateral Movement techniques ManySignal detects
Remote Services
RDP, SMB, SSH, and cloud VM connections used to pivot between hosts.
Use Alternate Authentication Material
Pass-the-Hash, Pass-the-Ticket, and web session cookie abuse for lateral auth.
Taint Shared Content
Modifying shared drives, code repos, or SharePoint files with malicious payloads.
Internal Spearphishing
Using compromised accounts to send phishing emails to other employees.
Remote Service Session Hijacking
Hijacking active RDP or SSH sessions on compromised hosts.
Lateral Movement: frequently asked questions
What is ATT&CK Lateral Movement (TA0008)?
Lateral Movement covers the techniques adversaries use to progressively move through a network to reach target systems. After gaining an initial foothold, attackers typically need to move laterally to reach high-value targets like domain controllers, backup systems, or sensitive data stores.
How does lateral movement differ in cloud environments?
In cloud environments, lateral movement often doesn't involve traditional network pivoting. Instead, attackers use compromised cloud credentials to access services directly (T1021.007 - Cloud Services) or chain role assumptions to reach higher-privilege accounts across different cloud services.
How does ManySignal correlate lateral movement across systems?
ManySignal builds a real-time entity graph that tracks authentication events, network connections, and process activity across all monitored systems. When a user authenticates to a new system in a lateral movement pattern, ManySignal correlates that event with the user's baseline access patterns to generate a contextual alert.
Stop lateral movement before attackers reach the crown jewels
ManySignal's entity graph correlates authentication and network events across all systems to detect lateral movement in under 5 minutes.