IronSights

Detection & response

Lateral movement

The technique used by attackers to progressively move through a network after initial compromise, gaining access to additional systems, data, and credentials en route to their ultimate target.

Also known asnetwork lateral movementeast-west movement

In plain English

Once an attacker is inside one device, they don't stop there. Lateral movement describes how they hop from machine to machine — using stolen credentials, exploiting vulnerabilities, or abusing trusted network relationships — until they reach the systems or data they're after. Network segmentation and the principle of least privilege limit how far an attacker can travel.

Keep learning

More terms in the IronSights Glossary.