Open links in new tab
  1. Detecting Lateral Movement with Splunk: How To Spot the Signs

    • Lateral movement is one of the key indicators for any time when you actually have an Advanced Persistent Threat (APT)in your network. Finding this lateral movement can be difficult because adversaries o… See more

    The Importance of Windows Event Logs

    First things first, if you’re not capturing Windows event logs from your endpoints, you're going to … See more

    Splunk
    Hunting For Lateral Movement

    When looking for lateral movement, we're identifying processes connecting remotely into a host. Our initial search could use Windows security logs, looking for authenticati… See more

    Splunk
    Exploring Hosts of Interest

    Using this information, we begin to lean in on hosts of interest. In particular, we see that the administrator has logged into host Win7-2 from IP address 192.168.237.134, which we'r… See more

    Splunk
    Hunting Using DCOM and DDE

    Distributed Component Object Model (DCOM) used withDynamic Data Exchange (DDE) allows an adversary to traverse the network using built-in tools. If you are not aware of D… See more

    Splunk
    Feedback
     
  1. Showing results for Splunk Movement
    Search instead of Slunk Movement
  2. Detecting Lateral Movement Using Splunk User …

    WEBAug 21, 2023 · Lateral movement consists of techniques that adversaries use to move across a compromised network after initial access. After exploring the targeted network, adversaries will move across …

  3. Lateral Movement model - Splunk Documentation

  4. Lateral Movement | Splunk Security Content

  5. What Is Lateral Movement? - Splunk

  6. How to Spot the Signs of Lateral Movement - Splunk Community

  7. Detecting Lateral Movement with Splunk - YouTube

  8. Slink Definition & Meaning - Merriam-Webster

  9. Analytics Story: Active Directory Lateral Movement | Splunk …

  10. Analytics Story: Lateral Movement - Splunk Security Content

  11. Showing results for Splunk Movement
    Search instead of Slunk Movement