You can trace an attacker's movement from one machine to another within your network after an initial compromise.
Use the Category filter to search for protocols commonly used for lateral movement, such as RDP, SSH, PsExec, WinRM, or WMI.
Examine the graph view. This visualization presents the data graphically, which helps identify patterns such as one host connecting to many others. A single source hexagon with arrows pointing to numerous other hosts can indicate an attacker exploring the network.
In the grid view, look for a single Src Acct or Src Host that has successfully connected to multiple different Tgt Host systems in a short time frame.