After the Breach: Why Attackers Move Freely Once They're Inside and How to Stop Them
The modern enterprise security stack is, in many respects, a triumph of engineering. Endpoint detection and response platforms, next-generation firewalls, and email gateways have collectively raised the cost of initial compromise to levels that would have seemed extraordinary a decade ago. Yet a persistent and largely unresolved problem sits one layer deeper: once an adversary establishes a foothold inside the network, the same organizations that blocked thousands of intrusion attempts often fail to detect a single attacker walking methodically from one system to the next.
This is the lateral movement problem, and it is not a niche concern. According to incident response data compiled across multiple major US enterprises, the median dwell time—the interval between initial compromise and detection—remains measured in days or weeks rather than hours. During that window, attackers are not idle. They are enumerating credentials, escalating privileges, and positioning themselves adjacent to the assets they ultimately intend to exfiltrate or encrypt.
Understanding why detection fails at this stage, and what can realistically be done about it, is among the most operationally relevant challenges facing enterprise IT security teams today.
Why the Perimeter Obsession Creates an Internal Blind Spot
Security investment has historically followed the threat model most visible to leadership: external attackers attempting to breach the network boundary. That framing is not wrong, but it is incomplete. It has produced organizations with highly instrumented perimeters and comparatively sparse internal visibility.
Traditional network segmentation was designed to contain blast radius, not to generate detection signals. A flat internal network is obviously dangerous, but even organizations that have invested in segmentation frequently discover that their VLAN boundaries and firewall rules were designed around application availability rather than adversary behavior. An attacker who obtains valid credentials—through phishing, credential stuffing, or purchasing access from an initial access broker—often finds that those credentials grant lateral reach that the network architecture never anticipated needing to restrict.
The problem compounds when security teams rely on perimeter-centric log sources. Firewall deny logs are voluminous and meaningful at the edge. Inside the network, where traffic between trusted hosts is expected and largely allowed, the same logs produce far less signal. Analysts reviewing internal east-west traffic frequently lack the baseline context necessary to distinguish legitimate administrative activity from an attacker using the same tools and protocols.
The Techniques Adversaries Rely On Most
Lateral movement is not a single technique but a category encompassing dozens of methods, many of which abuse legitimate operating system functionality. Several warrant specific attention because of their prevalence in documented US enterprise incidents.
Pass-the-Hash and Pass-the-Ticket remain stubbornly common despite being well-understood for years. When attackers extract NTLM hashes or Kerberos tickets from compromised hosts—often using tools like Mimikatz or its derivatives—they can authenticate to additional systems without ever knowing the plaintext password. Detection requires monitoring for authentication events that exhibit anomalous patterns: unusual source hosts, off-hours timing, or authentication against systems the source account has no documented reason to access.
Living-off-the-Land (LotL) techniques represent a more sophisticated evasion approach. Rather than deploying custom malware that endpoint tools might flag, attackers leverage built-in Windows utilities—PowerShell, WMI, PsExec, and scheduled tasks—to move laterally. Because these tools are used legitimately by IT administrators every day, distinguishing malicious use from routine operations requires behavioral baselining rather than simple signature matching.
Kerberoasting targets service accounts by requesting Kerberos service tickets for accounts with registered SPNs, then cracking those tickets offline. Service accounts frequently carry elevated privileges and are often configured with weak or static passwords, making them attractive stepping stones toward domain controller access.
SMB and RDP lateral movement remain reliable workhorses for attackers precisely because both protocols are widely permitted across internal segments. Monitoring for unusual RDP connections—particularly those originating from workstations rather than jump hosts—provides one of the more reliable lateral movement indicators available to defenders.
Why Traditional Segmentation Falls Short
Network segmentation is a necessary but insufficient control. Its limitations become apparent when considered against actual adversary behavior. Segmentation restricts which systems can communicate with which other systems, but it does not address the question of which credentials can authenticate where. An attacker operating with a compromised domain account may find that segmentation boundaries are largely irrelevant because their credentials are valid across segments.
Micro-segmentation addresses some of this by enforcing identity-aware policies at a more granular level, but implementation complexity is substantial. Many organizations that have pursued micro-segmentation projects report that accurately mapping application dependencies—a prerequisite for writing effective segmentation rules—takes far longer than anticipated, and that the process frequently reveals undocumented trust relationships that create exceptions eroding the control's effectiveness.
A Detection Framework Built for Internal Visibility
Closing the lateral movement detection gap requires a deliberate shift in instrumentation strategy. The following framework reflects practices that have demonstrated measurable impact in enterprise environments.
Establish behavioral baselines for privileged accounts. Detection without context is noise. Before meaningful anomaly detection is possible, security teams need documented baselines describing which accounts access which systems, at what times, and from which source hosts. Identity and access management platforms, combined with SIEM correlation rules, can automate much of this baseline construction, but the process requires sustained effort and periodic review.
Instrument authentication events comprehensively. Windows Security Event Logs contain the raw material for effective lateral movement detection, but only if they are collected, retained, and queried at scale. Event IDs 4624, 4625, 4648, 4768, 4769, and 4776 collectively cover the authentication events most relevant to lateral movement detection. Organizations that are not forwarding these events to a centralized SIEM with adequate retention are operating with a structural blind spot.
Deploy deception technology as a high-fidelity detection layer. Honeypot accounts, honey credentials embedded in memory, and decoy network shares generate alerts with exceptionally low false-positive rates. An attacker enumerating credentials who attempts to authenticate with a honey credential has, by definition, exhibited behavior that no legitimate user would replicate. For organizations with limited analyst capacity, deception technology provides a cost-effective mechanism for generating high-confidence lateral movement alerts.
Integrate network detection and response (NDR) tooling. Endpoint-centric detection misses attacker activity on systems where EDR agents are absent—legacy infrastructure, OT-adjacent systems, and network devices. NDR platforms that analyze east-west traffic patterns can identify lateral movement signatures including unusual SMB enumeration, atypical authentication sequences, and reconnaissance traffic that endpoint tools would never observe.
Define and enforce a tiered administrative access model. Privileged Access Workstations (PAWs), jump hosts, and tiered Active Directory administrative models limit the credential exposure that makes lateral movement possible in the first place. These are architectural controls rather than detection controls, but they reduce the attack surface that detection must cover.
Operationalizing the Response
Detection without a corresponding response capability merely informs the post-incident report. Security operations teams need pre-defined playbooks that specify the actions taken when lateral movement indicators fire: which accounts are disabled, which systems are isolated, and which stakeholders are notified at what thresholds. Tabletop exercises that simulate lateral movement scenarios—including adversary use of legitimate credentials—help validate that these playbooks function as intended before a real incident tests them.
The organizations that have made meaningful progress on this problem share a common characteristic: they treat internal visibility as a first-class security investment rather than an afterthought to perimeter hardening. That shift in priority, more than any specific tool or technique, is what separates enterprises that contain lateral movement quickly from those that discover it only after significant damage has been done.