← All terms

Lateral Movement

Lateral movement is how attackers spread from their first compromised account or device to the systems they actually want, reusing stolen credentials and trust.

Lateral movement is the set of techniques attackers use to expand from their initial foothold — one phished employee, one infected laptop — to the assets they actually came for: domain controllers, finance systems, source code, customer databases. Almost no intrusion starts where it intends to end. The first victim of a phishing email is rarely the target; they are the doorway, and lateral movement is the walk down the corridor.

How it works

Once inside, attackers loot the first machine for anything that opens a second one: cached passwords, browser-saved logins, session tokens, SSH keys, and shared-drive documents that mention other systems. They then reuse those credentials against internal services — RDP, SMB, VPN portals, cloud consoles — often using the same legitimate tools administrators use, so the traffic looks routine. Each new system yields more credentials, and each hop is chosen to escalate privilege or approach the objective. This is why a phished intern account can end in a domain-wide ransomware event: the intern's permissions were never the point, only the starting position. Excess permissions accumulated through privilege creep shorten the journey dramatically, because a single compromised account already opens far more doors than the attacker expected to need. The whole phase happens inside the dwell-time window, typically coordinated through a command-and-control channel.

How to defend against it

Assume the first compromise will happen and design the interior accordingly. Least privilege and regular access reviews shrink what any single stolen account can reach; network segmentation and zero-trust architecture turn one flat corridor into a series of locked doors; MFA on internal and administrative access — not just at the perimeter — makes replayed passwords useless. Monitor for the movement itself: first-time logins between systems, unusual admin-tool use, and service accounts behaving like humans. And shorten the runway at its start: an employee who reports the phish in the first minutes forces the attacker off the network before the second hop — one more reason detection speed, not prevention alone, decides how these incidents end, as our incident response guide details.

Related terms

Dwell TimeDwell time is how long an attacker operates inside a network before being detected — the window in which a foothold becomes a full breach.Command and Control (C2)Command and control (C2) is the covert channel malware uses to receive an attacker's instructions and send stolen data out — the remote hand on the compromised device.Privilege CreepPrivilege creep is the gradual buildup of access rights as people change roles and projects without ever losing old permissions — widening breach blast radius.Principle of Least PrivilegeLeast privilege means every user, process and system gets only the access it needs, for only as long as it needs it — limiting what a compromised account can do.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo