Lateral Movement
How an attacker moves from an initial foothold to other systems and accounts, often abusing identity and trust relationships. A primary target of identity threat detection.
Modern lateral movement is mostly identity work rather than exploitation: harvest a token, abuse a trust relationship between an on-premises directory and a cloud tenant, assume a role, or use a management platform that already has agents everywhere. That is why network segmentation alone does not stop it, and why the useful telemetry is authentication and authorization events rather than packets.
See also: privilege escalation, what is ITDR, token theft, Scattered Spider help desk social engineering
Related on Start with Identity
- GlossaryITDR
Identity Threat Detection and Response. Security tooling that detects and responds to identity-based attacks such as account takeover, privilege escalation, and
- GlossaryUEBA
User and Entity Behavior Analytics. Machine-learning analysis of normal behavior to flag anomalies that signal compromise or insider risk. A common building blo
- GlossaryAccount Takeover (ATO)
When an attacker gains control of a legitimate account, often via stolen credentials, phishing, or session theft. A leading cause of breaches and fraud. The dis
- BlogOkta buys Permiso Security to put ITDR inside the identity provider
Okta signed a definitive agreement to acquire Permiso Security, reportedly for just under 200 million dollars in an almost all-cash deal. It moves detection of
- BlogSilverfort acquires Fabrix Security, a one-year-old AI access-decision engine
Price undisclosed, reported as tens of millions for a company founded in 2025. Fabrix supplies the identity knowledge graph and decisioning; Silverfort supplies