Lateral Movement Analysis

Steve Anson · 2019

Modern attackers' tendency to use existing tools and protocols to embed themselves in and expand their influence throughout victim networks makes detection and response to lateral movement a critical skill for any incident handler. This chapter explores some common ways attackers use to move laterally in one's environment and highlights ways that people may be able to detect and respond to that activity. It presents a discussion on Server Message Block (SMB) protocol and looks at some specific attack vectors that rely on SMB under the hood, such as PsExec and scheduled task abuse. The chapter includes information on the pass-the-hash attack, the Kerberos default authentication mechanism, and golden and silver tickets. Leveraging all the techniques offered and applying them to all aspects of the cyber kill chain will improve a person's ability to respond to an adversary who has gained a foothold in his/her environment.

Read the paper · More papers on PaperTik