logo

MDR insights: Tracking lateral movement in a Windows environment (part I)

ID: aa137c4b-e454-5972-963a-566dcecb4e78

STIX ID: report--aa137c4b-e454-5972-963a-566dcecb4e78

Feed Name: Expel Blog

Date Published: 2024-12-19

Date Updated: 2026-04-27

Author: Brandon Overstreet

...
...

**Executive summary:** This guide consolidates Windows event-log detection and investigation techniques for lateral movement, describing relevant log files (%SYSTEMROOT%\System32\Winevt\Logs), key event IDs (e.g., 4624, 4688, 4698, 7045, 5140), and mappings to common attacker methods such as PowerShell remoting, PsExec/Impacket, RDP, scheduled tasks, service manipulation, and SMB network shares, and concludes with practical remediation actions (containment, artifact removal, and credential resets).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.