Know
What is Lateral Movement?
Adversary movement from one compromised identity or system to additional systems and resources inside an environment. In practice, lateral movement should be understood in the context of the identities, systems, applications, data, trust relationships, and business processes it affects. The useful question is not only what the term means, but how it changes attacker capability or defensive control.
Why it matters
Adversary movement from one compromised identity or system to additional systems and resources inside an environment. Attackers can use this behavior to turn a single weakness, identity, or interaction into broader compromise, so defenders need to recognize both the mechanism and the business consequence.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Fake IT-support contacts use Teams to obtain user-approved remote access
Microsoft describes external Teams contacts impersonating support staff and persuading users to grant remote access. The documented chain includes implant deployment, discovery, and lateral movement, following user authorization through legitimate support tools.
This is evidence of support-workflow abuse and social engineering. It does not establish a Teams software vulnerability or suggest that merely receiving a chat compromises a device.
MITRE and CISA document Active Directory credential abuse and lateral movement
MITRE ATT&CK documents Kerberoasting, Pass-the-Hash, forged Kerberos tickets, and use of alternate authentication material for lateral movement. CISA red-team and Active Directory guidance show these behaviors in realistic enterprise assessments and compromise scenarios.
It connects abstract Active Directory terminology to repeatable post-compromise techniques attackers use to expand access and preserve control.
Understand the mechanics
How it works
- 1
An adversary identifies a condition where lateral movement can provide access, control, information, or evasion.
- 2
The attacker executes the technique directly or combines it with credentials, social engineering, exploitation, or trusted tools.
- 3
Successful activity creates a new capability such as access, execution, persistence, privilege, movement, collection, or impact.
- 4
Defenders investigate the surrounding identity, host, application, network, and cloud telemetry to determine scope and interrupt the attack chain.
Practice
What to watch for
- Activity consistent with lateral movement in identity, endpoint, email, application, cloud, or network telemetry
- Unexpected authentication, privilege, execution, or data-access behavior
- New or unusual infrastructure, domains, processes, tokens, or administrative actions
- A sequence of events that matches a known adversary technique rather than normal business activity
Perform
What to do
- 1
Stop or contain the risky activity without destroying useful evidence.
- 2
Determine which identities, systems, applications, data, and sessions are affected.
- 3
Revoke exposed access, isolate compromised assets, and block malicious infrastructure as appropriate.
- 4
Hunt for related lateral movement activity and adjacent attacker behaviors before declaring the incident contained.
How to reduce the risk
- Collect endpoint, identity, network, and cloud telemetry.
- Map observed behavior to ATT&CK techniques.
- Detect unusual administrative behavior rather than relying only on malware signatures.
- Harden credentials, remote administration, and common lateral-movement paths.
Business impact
- Broader compromise
- Longer attacker dwell time
- Loss of detection coverage
- Operational disruption
What different roles should do
Employee / Operator
- Pause when an interaction or system behavior is unexpected.
- Use approved verification and reporting paths rather than improvising.
Security
- Correlate identity, endpoint, network, application, and cloud evidence.
- Contain the attack path and hunt for follow-on activity.
Framework & standards context
- MITRE ATT&CK TA0008
Source transparency
Authoritative sources
Last reviewed: 2026-09-02