Start with Identity
← Glossary
Threat

Lateral Movement

How an attacker moves from an initial foothold to other systems and accounts, often abusing identity and trust relationships. A primary target of identity threat detection.

Modern lateral movement is mostly identity work rather than exploitation: harvest a token, abuse a trust relationship between an on-premises directory and a cloud tenant, assume a role, or use a management platform that already has agents everywhere. That is why network segmentation alone does not stop it, and why the useful telemetry is authentication and authorization events rather than packets.

See also: privilege escalation, what is ITDR, token theft, Scattered Spider help desk social engineering

Last reviewed By SWI Community TeamSuggest a correctionHow we research