Trace lateral movement

Prev Next

You can trace an attacker's movement from one machine to another within your network after an initial compromise.

  • Use the Category filter to search for protocols commonly used for lateral movement, such as RDP, SSH, PsExec, WinRM, or WMI.

  • Examine the graph view. This visualization presents the data graphically, which helps identify patterns such as one host connecting to many others. A single source hexagon with arrows pointing to numerous other hosts can indicate an attacker exploring the network.

  • In the grid view, look for a single Src Acct or Src Host that has successfully connected to multiple different Tgt Host systems in a short time frame.