Lateral Movement · Learn

Lateral movement, in plain terms.

Lateral movement is how one compromised machine becomes many: reusing credentials and remote-execution tools to spread across the network, and tunneling through a foothold to reach systems that were never meant to be exposed. This section explains the real techniques and how to find them before an attacker does.

TL;DR

Lateral movement is the phase between owning one host and owning the network. This section breaks the execution techniques (PsExec, WMI, WinRM, SMB, DCOM, RDP) and the pivoting building blocks (reverse shells, port forwarding, SOCKS, chisel, ligolo-ng) into plain-language explainers with the real technical names, each ending with how a penetration test surfaces that path in your own environment.

By John Dill, Red Team Lead, SecureLayer7Updated

Topics

Key terms explained

Plain-language definitions of the techniques behind lateral movement and pivoting. Each page covers what it is, the attack, the payload, and how to defend.

Remote execution (Windows)

Shells and pivoting

Related (Active Directory)

How to read this section

The pages follow how an attacker actually spreads.

  • Foundations first: what lateral movement and pivoting are.
  • Remote execution: the Windows methods (PsExec, WMI, WinRM, SMB, DCOM, RDP) for running code on the next host.
  • Shells and pivoting: reverse and bind shells, then port forwarding, SSH tunneling, SOCKS, chisel, and ligolo-ng to reach internal networks.
  • Related: credential-reuse techniques from the Active Directory section (Pass-the-Hash, Pass-the-Ticket) that power most hops.

Each explainer ends with how a penetration test confirms the path in your own network.

References

  1. [1]MITRE ATT&CK: Lateral Movement (TA0008)(MITRE)
  2. [2]NIST SP 800-115 Technical Guide to Security Testing(NIST)
  3. [3]Microsoft: Administrative shares (C$, ADMIN$, IPC$)(Microsoft)
Related terms

Scope an engagement

Find the lateral-movement paths before an attacker does.

We run internal and network penetration tests that follow the real route from one compromised host across your network, then hand your team a report with reproducible evidence and a fix for every step. Free re-test included.

See all services30-min scoping call, fixed-price proposal in 48 hours.