Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should the extent of lateral movement be reported?

Report scope system by system and account by account, at the highest stage each source supports. One confirmed movement does not establish environment-wide compromise.

Use an evidence-based scope ladder

Separate systems that were scanned, contacted, authenticated to, controlled, used for data access or given persistence. Record unassessed systems separately from systems examined with evidence supporting no compromise.

State counts and findings precisely: connection attempts on twelve devices, successful authentication on two, process execution on one. Explain shared credentials or management platforms without assuming they were used everywhere they could reach.

Preserve uncertainty without inflating it

Logging and retention gaps may prevent a clean finding. Do not label those systems unaffected, but do not call them compromised merely because wider access was technically possible.

For each conclusion, identify the route, account, time and evidence. If containment or late examination reduced visibility, describe that limitation in the final scope assessment.

Key takeaway

Report attempts, access, control, impact and unknown status separately for each system instead of applying one broad compromise label.

Reference: CIM-142Cyber Incidents & Offender Methods