How should the extent of lateral movement be reported?¶
The practical answer¶
The extent of lateral movement should be reported at the level supported by evidence for each system or account.
The key evidential caution¶
The dangerous assumption is that one confirmed move justifies describing the whole environment as compromised.
It does not.
Separate:
Key points¶
- systems scanned
- systems contacted
- systems authenticated to
- systems controlled
- systems from which data was accessed
- systems with persistence
- systems whose status remains unknown
Use precise language.
For example:
“Authentication succeeded on two servers.”
“Connection attempts were recorded against twelve devices.”
“Process execution was confirmed on one host.”
“The available records do not establish whether the remaining systems were accessed.”
Explain any logging or retention gaps.
Evidential limits¶
Do not treat absence of evidence as proof of safety, but do not inflate the scope because wider access was technically possible.
Identify the route, account, time and evidence supporting each conclusion.
Practical interpretation¶
Where several systems are linked by one management platform or shared credential, explain that relationship.
The report should also distinguish confirmed lateral movement from legitimate administration and automated activity.
Where containment was staged, identify whether later systems were genuinely unaffected or simply examined after evidence had expired. Scope conclusions should distinguish confirmed clean findings from systems that could not be assessed fully.
State those evidential limits clearly in the final scope assessment.
Where systems were inaccessible or logs unavailable, record them as unassessed rather than unaffected.
This distinction avoids both understating and overstating the confirmed scale.
Operational takeaway¶
Report lateral movement system by system, separating attempts, successful access, control and unknown status rather than using one broad compromise label.