What is lateral movement?¶
Lateral movement is when somebody uses one foothold in an environment to reach another account, device or service.
That might be a workstation connecting to a server, one account being used on another machine, or an on-premises session moving into a cloud service.
The useful investigative job is to reconstruct each move from source โ target โ access method โ result.
Think of it as a series of jumps¶
Suppose an incident begins on FIN-LAP-07.
Network and account discovery reveal an internal server and a service account. A few minutes later the same source machine attempts to authenticate to FIN-SRV-04 using svc-backup.
svc-backup via remote serviceThe account, credential or access route used.That is one lateral-movement step.
If the server then connects to another system, treat that as another step and reconstruct it separately.
The target side matters¶
A connection attempt from the source is useful, but it does not by itself prove access succeeded.
Try to find the corresponding evidence on the target:
- authentication;
- session creation;
- remote-service logs;
- process execution;
- file access;
- or other activity after the login.
The strongest reconstruction usually joins both sides.
Discovery often explains why the move happened¶
This is where the earlier reconnaissance pages become useful.
If network discovery found FIN-SRV-04 and account discovery found svc-backup, those results may explain how the later source-to-target move developed.
The sequence of discovery activity helps show how those values can carry forward into later actions.
Movement can cross technologies¶
Lateral movement is not limited to one Windows computer connecting to another.
A route might involve:
- remote desktop;
- file-sharing services;
- SSH;
- management tools;
- browser sessions;
- federated identity;
- cloud tokens; or
- linked administrative platforms.
So do not force every transition into the same technical model. Preserve the actual access method and the records it produces.
Normal administration can look similar¶
Administrators legitimately connect from one system to another all the time.
Compare the activity with approved work, normal source devices, management platforms and expected accounts.
And remember that the source device may itself have been remotely controlled. Ownership of the laptop does not tell you who was driving the session.
The practical point is: prove each move as its own source-to-target event. Then join those events to show how the incident spread through the environment.