detecting-lateral-movement-in-network - Detect Lateral Movement Across Enterprise Networks
Analyzes authentication logs, network flows, SMB traffic, and RDP sessions with Zeek, Velociraptor, and SIEM rules to identify lateral movement.
Tags
Updated: 2026-10-03Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Collect Windows security logs
- Configure Zeek network logging
- Build SIEM detection rules
- Convert Sigma detection rules
- Detect SMB lateral spread
- Detect RDP lateral movement
- Hunt authentication anomalies
- Map potential attack paths
Inputs
- Windows security event logs
- DNS and flow data
- Zeek network logs
- SMB traffic logs
- RDP session data
- Authentication baselines
- Internal network topology
Outputs
- SIEM detection rules
- Sigma detection rules
- Zeek detection scripts
- Lateral movement alerts
- Threat hunting findings
- Attack path timelines
Requirements
- Internal network monitoring
- Zeek, Suricata, or network TAPs
- Splunk, Elastic, or Sentinel SIEM
- Windows event forwarding
- MITRE ATT&CK knowledge
- Normal communication baselines
