Detecting Lateral Movement with Splunk: How To Spot the Signs | Splunk
Once badness makes an inroad into your network, the adversary has a set of goals — steal credentials, persist, find the good stuff, exfiltrate the good stuff, and get paid! To do that, they need to move laterally. We have touched on two ways in which an adversary can traverse the network and we did this with only three sources of data — Windows Security, System events, and Sysmon. Other data sources like network metadata and registry entries can also be used for spotting lateral movement. (Part of our Threat Hunting with Splunk series, this article was originally written by Derek King. We’ve updated it recently to maximize your value.) Lateral movement is one of the key indicators for any time when you actually have an Advanced Persistent Threat (APT) in your network. Finding this lateral movement can be difficult because adversaries often use legitimate credentials to move around your network. Lateral movement happens in two ways: In this post, we’ll focus on using legitimate tools fo
Detecting Lateral Movement with Splunk: How To Spot the Signs | Splunk Detecting Lateral Movement with Splunk: How To Spot the Signs Security April 02, 2024 Madeleine Tauber , Tamara Chacon Once badness makes an inroad into your network, the adversary has a set of goals — steal credentials, persist, find the good stuff, exfiltrate the good stuff, and get paid! To do that, they need to move laterally. We have touched on two ways in which an adversary can traverse the network and we did this with only three sources of data — Windows Security, System events, and Sysmon. Other data sources like ne
Explore this link on the map →related reading
- Find lateral movement paths using KQL Graph semantics - Cloudbrotherscloudbrothers.info
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- A guide to threat hunting and monitoring in Snowflake | Datadog Security Labssecuritylabs.datadoghq.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com