High severityHARDEC6 steps · 6 phases
Lateral Movement Containment
Containment of lateral movement via RDP/SMB/PsExec/WMI/Pass-the-Hash.
Information note
Informational note: When covering lateral movement, first verify network segmentation and SMB/WMI/RDP access paths. Under MITRE T1021, Pass-the-Hash and token theft attacks propagate through admin shares; network isolation remains incomplete without simultaneously invalidating the affected credentials across the entire environment. Correlating Microsoft Defender for Identity or an equivalent behavioral analysis tool with network logs is mandatory to monitor lateral movement.
1
Preparation
1 steps- Network visibility
East-west traffic monitoring, EDR, AD session correlation.
2
Identification
1 steps- Extract the movement chain
Source/destination hosts, credentials used, lateral technique (PtH, RDP, WMI), timeline.
3
Containment
1 steps- Cut the path
Isolate affected hosts, lock compromised accounts, harden SMB/RDP, restrict network access.
4
Eradication
1 steps- Remove footholds