Bridging the Security Gap: Mitigating Lateral Movement Risks from On-Premises to Cloud Environments
ID: cbc587e7-96aa-5580-ac35-714720e585f8
STIX ID: report--cbc587e7-96aa-5580-ac35-714720e585f8
Feed Name: Wiz Blog
This blog explains common on‑premises to cloud lateral movement techniques and risks, including misuse of long‑lived or cached credentials and keys across AWS, Azure, and GCP, and AAD-specific methods such as Pass‑the‑PRT and Pass‑the‑Cookie. It highlights how attackers can exploit access keys, tokens, service principal secrets, service account keys, and SSH keys to pivot into cloud environments, and provides actionable mitigations such as minimizing local admins on AAD devices, enabling LSASS credential protection via ASR rules, shortening token lifetimes, preferring certificate-based auth, using cloud-managed shells, enforcing key expirations, and adopting IAM-mediated access (AWS SSM, GCP IAP) over direct SSH/RDP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
