detecting-lateral-movement-in-network - Detect Lateral Movement in Enterprise Networks
Identifies lateral movement by analyzing authentication logs, network flows, SMB traffic, and RDP sessions with Zeek, Velociraptor, and SIEM rules.
Tags
Updated: 2026-10-02Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Analyze authentication logs
- Correlate SIEM events
- Detect SMB movement
- Detect RDP movement
- Detect PsExec activity
- Detect pass-the-hash
- Hunt anomalous traffic
- Generate SIEM rules
- Configure Zeek detection
- Validate network segmentation
Inputs
- Windows Security Event Logs
- DNS and network flow data
- SMB and DCE-RPC logs
- RDP session data
- Internal authentication baseline
- Zeek logs
- SIEM data
Outputs
- Lateral movement alerts
- SIEM detection rules
- Sigma rule files
- Zeek detection notices
- Threat-hunting findings
- Attack-path timelines
Requirements
- Internal network monitoring
- SIEM platform
- Windows Event Forwarding
- Zeek, Suricata, or network TAPs
- MITRE ATT&CK knowledge
- Normal traffic baseline
- Monitoring configuration privileges
