MDR insights: Tracking lateral movement in a Windows environment (part 2)
ID: 556f509f-bbdb-56b7-96dd-7e812c3ea776
STIX ID: report--556f509f-bbdb-56b7-96dd-7e812c3ea776
Feed Name: Expel Blog
This blog-style pocket guide provides a concise reference for tracking lateral movement on Windows systems (part two of a series). It outlines four common techniques—DCOM, netsh portproxy, WinRM, and WMI—identifies the relevant Windows Security, WFP, and Sysmon event IDs to monitor (e.g., 4624, 4672, 4688, 5156, 5154, 5447, 5857, 5860, 5861), describes suspicious process and network indicators to look for, and recommends immediate remediation actions such as isolating affected hosts, disabling NICs or compromised accounts, and terminating active sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
