The objective is to move closer to valuable data or operational targets, expand reach, or establish alternative paths. Movement may cross endpoints, servers, identity systems, cloud resources, network segments, or information technology and operational technology boundaries.
Adversaries may reuse credentials, tokens, administrative shares, remote services, management platforms, trusted relationships, or vulnerabilities. The activity can resemble legitimate administration, especially when valid accounts and native tools are used. Investigation therefore needs identity, endpoint, network, cloud-control-plane, and administrative evidence tied together over time.
Key points
Common enablersExcessive privileges, credential reuse, broad reachability, unmanaged trust paths, exposed remote services, and weak separation between administrative tiers can make movement easier.
Observable patternsNew remote sessions, unusual account-to-host combinations, internal service exploitation, credential access followed by remote use, and tools appearing across several systems may warrant correlation.
Defensive prioritiesEnforce least privilege and segmentation, protect privileged credentials, restrict and monitor remote administration, centralize relevant logs, and prepare containment actions that preserve evidence and essential services.
Important limitationA remote login or east–west connection is not proof of lateral movement. Conversely, segmentation can constrain paths but cannot stop movement through allowed services, compromised identities, shared control planes, or overlooked dependencies.