mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
41 lines
2.6 KiB
YAML
41 lines
2.6 KiB
YAML
name: Lateral Movement
|
|
id: 399d65dc-1f08-499b-a259-aad9051f38ad
|
|
version: 2
|
|
date: '2020-02-04'
|
|
description: Detect and investigate tactics, techniques, and procedures around how
|
|
attackers move laterally within the enterprise. Because lateral movement can expose
|
|
the adversary to detection, it should be an important focus for security analysts.
|
|
narrative: "Once attackers gain a foothold within an enterprise, they will seek to\
|
|
\ expand their accesses and leverage techniques that facilitate lateral movement.\
|
|
\ Attackers will often spend quite a bit of time and effort moving laterally. Because\
|
|
\ lateral movement renders an attacker the most vulnerable to detection, it's an\
|
|
\ excellent focus for detection and investigation.\\\nIndications of lateral movement\
|
|
\ can include the abuse of system utilities (such as `psexec.exe`), unauthorized\
|
|
\ use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash,\
|
|
\ or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting\
|
|
\ lateral movement techniques and look for suspicious activity in and around high-value\
|
|
\ strategic network assets, such as Active Directory, which are often considered\
|
|
\ the primary target or \"crown jewels\" to a persistent threat actor.\\\nAn adversary\
|
|
\ can use lateral movement for multiple purposes, including remote execution of\
|
|
\ tools, pivoting to additional systems, obtaining access to specific information\
|
|
\ or files, access to additional credentials, exfiltrating data, or delivering a\
|
|
\ secondary effect. Adversaries may use legitimate credentials alongside inherent\
|
|
\ network and operating-system functionality to remotely connect to other systems\
|
|
\ and remain under the radar of network defenders.\\\nIf there is evidence of lateral\
|
|
\ movement, it is imperative for analysts to collect evidence of the associated\
|
|
\ offending hosts. For example, an attacker might leverage host A to gain access\
|
|
\ to host B. From there, the attacker may try to move laterally to host C. In this\
|
|
\ example, the analyst should gather as much information as possible from all three\
|
|
\ hosts. \\\n It is also important to collect authentication logs for each host,\
|
|
\ to ensure that the offending accounts are well-documented. Analysts should account\
|
|
\ for all processes to ensure that the attackers did not install unauthorized software."
|
|
author: David Dorsey, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html
|
|
tags:
|
|
analytics_story: Lateral Movement
|
|
usecase: Advanced Threat Detection
|
|
category:
|
|
- Adversary Tactics
|