logo

Investigating Darktrace alerts for lateral movement

ID: 5cbee92e-c2be-52c8-bb35-ea1a1bff8317

STIX ID: report--5cbee92e-c2be-52c8-bb35-ea1a1bff8317

Feed Name: Expel Blog

Date Published: 2018-06-21

Date Updated: 2026-04-27

Author: Tyler Fornes

...
...

This post describes how Expel analysts leverage Darktrace to triage and investigate model-breach alerts, focusing on detecting and analyzing lateral movement via SMB (remote file copy, T1105). It details useful Darktrace features (advanced log search, full packet capture, asset identification), a step-by-step investigation of a Scheduled Task model breach, and how to validate findings with historical logs and PCAP extraction, ultimately concluding the observed activity was legitimate administrative behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.