Terminology Index

Glossary

2953 terms

Open concept maps
L
32

Lateral Movement Hunts

Threat hunts focused on finding attacker movement between systems inside a network, searching for signs of remote access, credential reuse, and pivoting that indicate an intruder spreading from an initial foothold.

After gaining a foothold, attackers move laterally to reach their objectives, and lateral movement hunts proactively search for that activity: unusual remote logons, use of administrative tools across hosts, credential reuse, and pivoting patterns. Forming a hypothesis about how an adversary would move in the environment, hunters examine authentication and host telemetry for these signs, aiming to catch an intrusion mid-spread that point detections missed. It is a high-value tactic-focused hunt.

Introduced in: Threat Hunting Fundamentals

Examples

  • Hunting for unusual remote logons between internal hosts.
  • Searching for admin tools being used across many systems.
  • Looking for credential reuse indicating pivoting from a foothold.