Terminology Index
Glossary
2953 terms
Lateral Movement Hunts
Threat hunts focused on finding attacker movement between systems inside a network, searching for signs of remote access, credential reuse, and pivoting that indicate an intruder spreading from an initial foothold.
After gaining a foothold, attackers move laterally to reach their objectives, and lateral movement hunts proactively search for that activity: unusual remote logons, use of administrative tools across hosts, credential reuse, and pivoting patterns. Forming a hypothesis about how an adversary would move in the environment, hunters examine authentication and host telemetry for these signs, aiming to catch an intrusion mid-spread that point detections missed. It is a high-value tactic-focused hunt.
Introduced in: Threat Hunting Fundamentals
Examples
- Hunting for unusual remote logons between internal hosts.
- Searching for admin tools being used across many systems.
- Looking for credential reuse indicating pivoting from a foothold.
