GlossarySOC and monitoring

Lateral movement

Short answer

Lateral movement is the set of techniques attackers use to move from the first compromised system to others inside a network, looking for valuable data, administrator accounts and backups. It is the stage between initial access and the final impact, such as ransomware or data theft.

How attackers move

They reuse stolen credentials and password hashes, connect through remote desktop, SMB or remote management tools, exploit unpatched internal systems and abuse legitimate administration tools so that their activity blends in. MITRE ATT&CK catalogues these techniques as a separate tactic.

Why it matters

One infected laptop is rarely the goal. Ransomware groups typically spend days or weeks moving through the network, gaining domain administrator rights and locating backups before encrypting everything at once. Stopping lateral movement turns a serious incident into a contained one.

Limiting it

Network segmentation, so that workstations cannot reach servers or each other freely. Privileged access management and separate administrator accounts that are never used for email or browsing. Unique local administrator passwords on every machine, for example with Windows LAPS. MFA on remote access and administrative tools, and least privilege everywhere.

Detecting it

EDR and centralised logs can reveal typical signs: one account logging in to many machines in a short time, administrative tools used from unusual hosts, or connections between workstations that normally do not talk to each other. These signals are most useful when someone reviews them and acts quickly.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub