How attackers move
They reuse stolen credentials and password hashes, connect through remote desktop, SMB or remote management tools, exploit unpatched internal systems and abuse legitimate administration tools so that their activity blends in. MITRE ATT&CK catalogues these techniques as a separate tactic.
Why it matters
One infected laptop is rarely the goal. Ransomware groups typically spend days or weeks moving through the network, gaining domain administrator rights and locating backups before encrypting everything at once. Stopping lateral movement turns a serious incident into a contained one.
Limiting it
Network segmentation, so that workstations cannot reach servers or each other freely. Privileged access management and separate administrator accounts that are never used for email or browsing. Unique local administrator passwords on every machine, for example with Windows LAPS. MFA on remote access and administrative tools, and least privilege everywhere.
Detecting it
EDR and centralised logs can reveal typical signs: one account logging in to many machines in a short time, administrative tools used from unusual hosts, or connections between workstations that normally do not talk to each other. These signals are most useful when someone reviews them and acts quickly.




