Lateral Movement Detection Rules
The adversary is trying to move through your environment. Lateral Movement consists of techniques that adversaries use to enter and control remote systems on a network. Following through on their primary objective often requires exploring the network to find their target, then pivoting through multiple systems and accounts to gain access to it. Adversaries might install their own remote access tools to accomplish Lateral Movement or use legitimate credentials with native network and operating system tools, which may be stealthier.
df00tech ships 113 production-ready detection rules mapped to the Lateral Movement tactic (TA0008). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Lateral Movement detections (113)
- CVE-2008-4250 MS08-067 NetAPI Buffer Overflow Exploitation Attempt (CVE-2008-4250)
- CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted File Upload Exploitation
- CVE-2020-7796 Zimbra Collaboration Suite SSRF Exploitation (CVE-2020-7796)
- CVE-2021-22054 Omnissa Workspace ONE UEM Server-Side Request Forgery (CVE-2021-22054)
- CVE-2021-22175 GitLab SSRF Exploitation (CVE-2021-22175)
- CVE-2021-22681 Rockwell Automation Logix Controllers Insufficient Credential Protection (CVE-2021-22681)
- CVE-2021-26829 OpenPLC ScadaBR Cross-Site Scripting (XSS) Exploitation Detected
- CVE-2021-39935 GitLab SSRF via Import Feature (CVE-2021-39935)
- CVE-2022-37055 CVE-2022-37055 D-Link Router Buffer Overflow Exploitation
- CVE-2023-4346 KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout (CVE-2023-4346)
- CVE-2024-1708 ConnectWise ScreenConnect Path Traversal (CVE-2024-1708)
- CVE-2024-3400 Palo Alto PAN-OS GlobalProtect Command Injection (CVE-2024-3400)
- CVE-2024-21182 Oracle WebLogic Server CVE-2024-21182 Exploitation Attempt
- CVE-2024-21413 CVE-2024-21413: Microsoft Outlook RCE via Moniker Link (MonikerLink)
- CVE-2024-21887 Ivanti Connect Secure Authenticated Command Injection (CVE-2024-21887)
- CVE-2024-30078 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution via Adjacent Network
- CVE-2024-37079 VMware vCenter Server Out-of-bounds Write (CVE-2024-37079)
- CVE-2024-43451 CVE-2024-43451: Windows NTLM Hash Disclosure via File Interaction
- CVE-2024-43468 CVE-2024-43468: Microsoft Configuration Manager SQL Injection Exploitation
- CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability (CVE-2024-57726)
- CVE-2025-6204 CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection
- CVE-2025-11953 React Native Community CLI OS Command Injection (CVE-2025-11953)
- CVE-2025-20393 CVE-2025-20393 — Cisco Multiple Products Improper Input Validation (KEV)
- CVE-2025-24054 Windows NTLM Credential Leak via File Download Interaction
- CVE-2025-24893 CVE-2025-24893 XWiki Platform Eval Injection Exploitation
- CVE-2025-32975 Quest KACE SMA Improper Authentication Exploitation Detected
- CVE-2025-34026 Versa Concerto Improper Authentication (CVE-2025-34026)
- CVE-2025-34291 CVE-2025-34291: Langflow Origin Validation Error Exploitation
- CVE-2025-37164 HPE OneView Code Injection Exploitation (CVE-2025-37164)
- CVE-2025-40602 CVE-2025-40602 - SonicWall SMA1000 Missing Authorization Exploitation
- CVE-2025-53521 F5 BIG-IP Stack-Based Buffer Overflow Exploitation (CVE-2025-53521)
- CVE-2025-58034 Fortinet FortiWeb OS Command Injection (CVE-2025-58034)
- CVE-2025-59287 Microsoft WSUS Deserialization of Untrusted Data (CVE-2025-59287)
- CVE-2025-59374 ASUS Live Update Embedded Malicious Code (CVE-2025-59374)
- CVE-2025-61932 Motex LANSCOPE Endpoint Manager - Improper Verification of Communication Channel Source (CVE-2025-61932)
- CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection (CVE-2025-66644)
- CVE-2025-67038 CVE-2025-67038 Lantronix EDS5000 Code Injection Exploitation
- CVE-2025-68613 n8n Improper Control of Dynamically-Managed Code Resources (CVE-2025-68613)
- CVE-2026-1340 Ivanti EPMM Code Injection Exploitation (CVE-2026-1340)
- CVE-2026-1603 Ivanti Endpoint Manager (EPM) Authentication Bypass (CVE-2026-1603)
- CVE-2026-1731 BeyondTrust Remote Support Pre-Auth RCE (CVE-2026-1731)
- CVE-2026-9082 Drupal Core SQL Injection Exploitation (CVE-2026-9082)
- CVE-2026-10520 Ivanti Sentry OS Command Injection Exploitation (CVE-2026-10520)
- CVE-2026-12569 CVE-2026-12569 - PTC Windchill and FlexPLM Improper Input Validation / Unsafe Deserialization
- CVE-2026-20045 CVE-2026-20045: Cisco Unified Communications Manager Code Injection
- CVE-2026-20122 Cisco Catalyst SD-WAN Manager Privileged API Abuse (CVE-2026-20122)
- CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format (CVE-2026-20128)
- CVE-2026-20131 Cisco FMC/SCC Deserialization RCE Exploitation (CVE-2026-20131)
- CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182)
- CVE-2026-20230 Cisco Unified Communications Manager SSRF Exploitation Detected
- CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Output Encoding Exploitation
- CVE-2026-22719 CVE-2026-22719: VMware Aria Operations Command Injection
- CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Hard-coded Credentials Exploitation
- CVE-2026-24061 GNU InetUtils Argument Injection Vulnerability (CVE-2026-24061)
- CVE-2026-25089 Fortinet FortiSandbox OS Command Injection (CVE-2026-25089)
- CVE-2026-30120 Remotion RCE via Code Injection (CVE-2026-30120)
- CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation (CVE-2026-32201)
- CVE-2026-34908 CVE-2026-34908 — Ubiquiti UniFi OS Improper Access Control Exploitation
- CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability (CVE-2026-34910)
- CVE-2026-35616 CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Exploitation
- CVE-2026-42271 BerriAI LiteLLM Command Injection (CVE-2026-42271)
- CVE-2026-44180 CVE-2026-44180: Jupyter Enterprise Gateway ContainerProcessProxy._enforce_prohibited_ids Bypass
- CVE-2026-45579 DIRAC RequestManager eval() Remote Code Execution (CVE-2026-45579)
- CVE-2026-46595 CVE-2026-46595: golang.org/x/crypto/ssh VerifiedPublicKeyCallback Authentication Bypass
- CVE-2026-47137 CVE-2026-47137 — vm2 Sandbox Escape via nesting:true Bypass (RCE)
- CVE-2026-47140 CVE-2026-47140 — vm2 Builtin Denylist Bypass via process/inspector Leads to Host RCE
- CVE-2026-47208 CVE-2026-47208: vm2 Sandbox Breakout via Promise Species
- CVE-2026-47392 PraisonAI Sandbox Escape via print.__self__ Builtins Leak in execute_code
- CVE-2026-47428 CVE-2026-47428: Vitest Browser Mode XSS via Unsanitized otelCarrier Query Parameter
- CVE-2026-47724 nebula-mesh API Ownership Check Bypass — Cross-Operator Privilege Escalation
- CVE-2026-48030 Pheditor OS Command Injection via Unsanitized 'dir' Parameter (CVE-2026-48030)
- CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-48172)
- CVE-2026-48282 CVE-2026-48282: Adobe ColdFusion Path Traversal Exploitation
- CVE-2026-48558 CVE-2026-48558 — SimpleHelp Authentication Bypass (CWE-347)
- CVE-2026-48751 CVE-2026-48751: Incus Restricted Project Bypass Leading to Arbitrary Command Execution
- CVE-2026-48752 Incus Arbitrary File Read/Write via Malicious Image Template Symlink
- CVE-2026-48753 CVE-2026-48753: Incus S3 Multipart Upload Path Traversal Arbitrary File Write
- CVE-2026-48755 Incus Argument Injection in Backup Compression Algorithm (CVE-2026-48755)
- CVE-2026-49980 Rclone RCD Unauthenticated Command Execution via Inline Remote Instantiation (CVE-2026-49980)
- CVE-2026-50545 CVE-2026-50545: Fission Environment CRD PodSpec Injection
- CVE-2026-50563 Fission Container Executor PodSpec Injection - Node Escape Attempt
- CVE-2026-50564 Fission Environment CRD PodSpec Passthrough Node Escape (CVE-2026-50564)
- CVE-2026-52806 CVE-2026-52806: Gogs RCE via git rebase --exec Argument Injection in PR Merge
- CVE-2026-52813 Gogs Path Traversal in Organization Name Leading to RCE via Git Hooks
- CVE-2026-55166 CVE-2026-55166: Lemur ACME SSRF and IDOR Leading to AWS IAM/PKI Compromise
- CVE-2026-56266 Crawl4AI Docker API Multiple Critical Vulnerabilities (File Write, SSRF, Auth Bypass, XSS, JS Execution)
- T1021 Remote Services
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1021.003 Distributed Component Object Model
- T1021.004 SSH
- T1021.005 VNC
- T1021.006 Windows Remote Management
- T1021.007 Cloud Services
- T1021.008 Direct Cloud VM Connections
- T1051 Shared Webroot
- T1072 Software Deployment Tools
- T1080 Taint Shared Content
- T1091 Replication Through Removable Media
- T1175 Component Object Model and Distributed COM
- T1210 Exploitation of Remote Services
- T1534 Internal Spearphishing
- T1550 Use Alternate Authentication Material
- T1550.001 Application Access Token
- T1550.002 Pass the Hash
- T1550.003 Pass the Ticket
- T1550.004 Web Session Cookie
- T1563 Remote Service Session Hijacking
- T1563.001 SSH Hijacking
- T1563.002 RDP Hijacking
- T1570 Lateral Tool Transfer
- THREAT-LateralMovement-SMBPsExec Lateral Movement via SMB and PsExec-Style Remote Execution
- THREAT-Ransomware-StagingIndicators Ransomware Pre-Deployment Staging Indicators
Related tactics
266 detections
225 detections