Basyrix SOC Response Atlas by Basyrix

Lateral Movement

T1021 — Remote Services

Adversaries may use valid accounts to log into remote services — RDP, SSH, SMB/admin shares, WinRM, VNC — for lateral movement across an environment using legitimate remote access functionality.

Review any remote-service logon that is unusual for the source host, destination host, account, or time — particularly an account authenticating to a system it does not normally access, or a workstation connecting directly to another workstation rather than through expected jump hosts.

Platforms

Windows, Linux, macOS

Priority / status

medium / complete

Evidence to collect

  • Source and destination host
  • Account used
  • Remote service/protocol (RDP/SSH/SMB/WinRM/VNC)
  • Logon timestamp and type
  • Activity performed on the destination after logon