What is Lateral Movement?
Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment. Adversaries can use valid credentials, tokens, remote services, shared content, deployment tools, session hijacking, or vulnerabilities. It is a tactic used to reach an objective, not the objective itself. It can occur in cloud services as well as traditional networks.
Why it matters
One compromised account or host can become a path to more valuable resources. Each successful move can add credentials, privileges, data, and new paths for the adversary.
How it works
- The adversary uses an existing foothold to discover reachable systems, services, accounts, and trust relationships.
- The adversary obtains or reuses authentication material, hijacks a session, abuses a management tool, or exploits a remote service.
- The adversary enters another system or account, performs actions there, and can repeat the process toward the objective.
Example
An adversary steals a build-service token, uses it to enter a deployment platform, and then uses the platform's trusted production connection to reach another system.
Pomerium boundary
Pomerium can reduce one lateral-movement path by applying identity and context policy to protected application and administration routes. Authorization logs can record each Pomerium access decision. Pomerium does not inspect arbitrary east-west traffic, detect endpoint malware, or protect a route that bypasses it.
Limits and non-claims
- Lateral movement follows an initial compromise and does not describe every later objective such as collection, exfiltration, or impact.
- Legitimate credentials and administration tools can make malicious movement look like normal work.
- One proxy, segmentation rule, or detection source cannot cover every account, host, cloud service, and alternate path.
Evaluation checklist
- Which compromised identity, workload, device, or credential gives the attacker a starting point?
- Which neighboring services, secrets, control planes, and data stores become reachable next?
- Do narrow identity, segmentation, credential scope, detection, and containment stop each step?
