How Huntress Addresses Lateral Movement
ID: 6796ec42-c5c5-5f56-a68e-99c14f1c7a97
STIX ID: report--6796ec42-c5c5-5f56-a68e-99c14f1c7a97
Feed Name: Huntress Blog
Huntress describes a layered EDR approach to detect lateral movement by focusing on four action pillars (initial execution, transport, remote authentication, remote execution), prioritizing telemetry around remote authentication and execution (source IP/port/hostname, logon type/id). The write-up details detection examples and real-world observations—including MMC/DCOM abuse to execute PowerShell, credential dumping via mmc.exe/rundll32, and activity consistent with ransomware preparation (deleting shadow copies, staging sensitive files)—and explains how this telemetry increases detection fidelity and SOC response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
