MDR insights: Tracking lateral movement in a Windows environment (part I)
ID: aa137c4b-e454-5972-963a-566dcecb4e78
STIX ID: report--aa137c4b-e454-5972-963a-566dcecb4e78
Feed Name: Expel Blog
**Executive summary:** This guide consolidates Windows event-log detection and investigation techniques for lateral movement, describing relevant log files (%SYSTEMROOT%\System32\Winevt\Logs), key event IDs (e.g., 4624, 4688, 4698, 7045, 5140), and mappings to common attacker methods such as PowerShell remoting, PsExec/Impacket, RDP, scheduled tasks, service manipulation, and SMB network shares, and concludes with practical remediation actions (containment, artifact removal, and credential resets).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
