Skip to main content

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

What is Lateral Movement?

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment. Adversaries can use valid credentials, tokens, remote services, shared content, deployment tools, session hijacking, or vulnerabilities. It is a tactic used to reach an objective, not the objective itself. It can occur in cloud services as well as traditional networks.

Why it matters

One compromised account or host can become a path to more valuable resources. Each successful move can add credentials, privileges, data, and new paths for the adversary.

How it works

  1. The adversary uses an existing foothold to discover reachable systems, services, accounts, and trust relationships.
  2. The adversary obtains or reuses authentication material, hijacks a session, abuses a management tool, or exploits a remote service.
  3. The adversary enters another system or account, performs actions there, and can repeat the process toward the objective.

Example

An adversary steals a build-service token, uses it to enter a deployment platform, and then uses the platform's trusted production connection to reach another system.

Pomerium boundary

Pomerium can reduce one lateral-movement path by applying identity and context policy to protected application and administration routes. Authorization logs can record each Pomerium access decision. Pomerium does not inspect arbitrary east-west traffic, detect endpoint malware, or protect a route that bypasses it.

Limits and non-claims

  • Lateral movement follows an initial compromise and does not describe every later objective such as collection, exfiltration, or impact.
  • Legitimate credentials and administration tools can make malicious movement look like normal work.
  • One proxy, segmentation rule, or detection source cannot cover every account, host, cloud service, and alternate path.

Evaluation checklist

  • Which compromised identity, workload, device, or credential gives the attacker a starting point?
  • Which neighboring services, secrets, control planes, and data stores become reachable next?
  • Do narrow identity, segmentation, credential scope, detection, and containment stop each step?

Sources and further reading

Keep learning

Network and Infrastructure

East-West Traffic

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.

Learn this term
Zero TrustNetwork and Infrastructure

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

Learn this term
Security Operations and Risk

Ransomware

Ransomware is malware used to deny access to data or systems and demand payment. Many operators also steal data and threaten disclosure.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo