Build a Lateral Movement Detection From Behavior
Create a behavior-based detection concept for lateral movement using ATT&CK language.
A workstation authenticates to eight servers over SMB and creates a remote service, but the legacy rule only detects a known malware hash. ATT&CK detection engineering: map behavior to tactic and technique, identify observables, add context, and write a response note. Hash-only detections age quickly. They may be quiet because the attacker changed tools, not because the behavior stopped. Map behavior Describe the activity as lateral movement using SMB authentication fan-out and remote service creation. ATT&CK language makes the detection about the attacker objective, not a single tool. Choose observables Use authentication logs, SMB connection telemetry, service creation events, and…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in