Select Page

Lateral Movements: Best Practices to Protect your Network

Lateral movement and credential theft have been present in almost all attempted attacks in the last 10 years; it is essential for organizations to prioritize early response and alerts against this typ...

Lateral movement and credential theft have been present in almost all attempted attacks in the last 10 years; it is essential for organizations to prioritize early response and alerts against this type of technique.

What is Lateral Movement?

Lateral movements are computer hacker attack techniques that are used to spread through a network, searching for assets and key information. To increase the chances of finding the key location or data, a hacker will almost always resort to these lateral movement techniques.

Most of these techniques are based on the use of privileged credentials and techniques that mimic what Windows domain administrators do every day; this is precisely what makes detection so difficult for most organizations, assuming that antimalware tools cannot detect the set of malicious tools.

 

lateral movement mitigation actions cybersecurity

 

Actions to Take for Mitigation

1. Apply the principle of least privilege.

Limiting the distribution of privileged accounts and monitoring the use of privileged credentials in real time is essential to start detecting lateral movements within the network. Network users must have accounts and tiered access according to the criteria and policies set by the administrator.

2. Implement a whitelist for applications.

That only allows legitimate applications to run on the network and records all attempts to start other applications. Application whitelists are not a foolproof solution for adversary mitigation, but they can make it difficult for exploits to act and make hackers make more noise, which increases the chances of detection.

3. Use two-factor authentication (2FA)

The number of systems that still use single-factor authentication to manage account and network access is alarming. Enabling 2FA on systems that support it, and especially on any web application with an Internet connection, can help improve your chances of avoiding privilege escalation that allows lateral movement.

4. Create automated secure passwords and increase account protection.

In addition to 2FA, your company can benefit from the additional layer of security that automated password protocols and SSH key management tools can provide. The unique passwords used by these tools eliminate a considerable portion of brute force attacks.

5. Use IDS-type technologies to detect a possible intrusion breach.

A considerable vulnerability for computer hackers is to take advantage of port scanning to determine their location. An intrusion detection system (IDS) connected to the network will detect signals from the port scan so that it sends us an alert before it is too late.

6. Use managed services and early alert detection.

Use managed services to respond to threats, including new threat search, detection, and response systems that combine machine learning technology with expert consultant analysis to neutralize complex attacks through different vectors