TL;DR: Modern attackers complete breakout sequences in 29 minutes on average, while many organisations still face 70-minute investigation timelines and 56-minute SOC delays, according to CrowdStrike’s 2026 Global Threat Report and D3’s analysis. The gap is no longer about seeing alerts, but correlating identity, endpoint, network, and cloud evidence fast enough to contain the full attack path.
NHIMG editorial — based on content published by D3: Lateral movement detection tools vs. attack path discovery
By the numbers:
- 90% of organizations experienced lateral movement in their last breach.
- The average eCrime attacker achieves a complete breakout in just 29 minutes.
Questions worth separating out
Q: What breaks when lateral movement detection tools only see isolated alerts?
A: Teams lose the attack sequence.
Q: Why do valid credentials make lateral movement so hard to detect?
A: Valid credentials let attackers appear to be normal users or administrators, so the traffic often blends into routine operations.
Q: How do you know if attack path discovery is actually improving response?
A: Look for shorter time to reconstruct the attacker’s route, fewer uninvestigated alerts, and faster containment of affected systems.
Practitioner guidance
- Map identity-to-lateral-movement dependencies Trace which privileged accounts, cached credentials, service accounts, and remote access paths can be used to move from a low-value endpoint to sensitive servers.
- Unify detection around attack-path reconstruction Link endpoint, SIEM, NDR, cloud, and identity telemetry into a single investigation workflow that reconstructs the sequence of events rather than forcing analysts to compare isolated alerts.
- Shorten privileged access persistence windows Reduce the time credentials, tokens, and admin sessions remain reusable after initial compromise.
What's in the full article
D3's full analysis covers the operational detail this post intentionally leaves for the source:
- How its attack path discovery model correlates endpoint, network, identity, cloud, data, and application telemetry in a single view
- What the 800+ integration environment means for investigation coverage and visibility gaps
- The runtime playbook generation flow and what analysts see during a live incident
- The under-2-minute narrative reconstruction example compared with traditional alert triage
👉 Read D3's analysis of attack path discovery versus lateral movement detection →
Attack path discovery vs lateral movement detection: are your controls keeping up?
Explore further
Attack path visibility is now an identity governance problem, not just a SOC problem. When attackers move with legitimate credentials, the decisive control is no longer a single alert source but whether the organisation can connect identity, endpoint, and network evidence into one sequence. That makes access telemetry and privilege context part of operational governance, not merely detection plumbing. Practitioners should treat correlation across identity and infrastructure as a core control objective.
A question worth separating out:
Q: Who is accountable when lateral movement controls are missing?
A: Accountability should sit with both security leadership and the teams that own identity, platform, and network policy, because lateral movement is a shared control problem. Frameworks such as NIST CSF and OWASP NHI make it clear that internal access, visibility, and containment are governance responsibilities, not optional hardening tasks. Ownership must be explicit before an incident forces the issue.
👉 Read our full editorial: Lateral movement detection is too slow for modern attack paths