Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that a campaign has…
Threats, Abuse & Incident Response

What are the signs that a campaign has moved beyond initial infection into persistence and lateral movement?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Threats, Abuse & Incident Response

Common signs include new scheduled tasks, unusual PowerShell or MSHTA execution, web shell activity, repeated authentication attempts, and unexpected connections to command and control infrastructure. If the attacker also starts using internal administrative systems, domain controllers, or remote shells, the intrusion has likely progressed beyond a single endpoint and into broader operational control.

How to tell the intrusion has progressed beyond the first foothold

The shift from initial infection to persistence and lateral movement is usually visible in the attacker’s behaviour, not just in one endpoint alert. Watch for artefacts that suggest the actor is trying to survive reboots, expand access, and operate from within trusted systems. The key change is that the campaign stops looking like isolated malware execution and starts looking like a managed intrusion.

Persistence indicators often appear first as changes that create repeatable access, such as new scheduled tasks, startup entries, services, or autoruns. Those same behaviours become more concerning when they are paired with administrative tooling, encoded scripts, or unusual use of living-off-the-land binaries such as PowerShell or MSHTA.

Lateral movement usually shows up when activity spreads beyond the original host and begins touching internal infrastructure that should not be needed for a single compromised workstation. That includes remote shell use, repeated authentication attempts, access to domain controllers, and connections that line up with command and control infrastructure rather than normal business traffic.

What persistence looks like in practice

Persistence is about making the compromise durable enough that the attacker can return after reboots, user logoff, or routine cleanup. The strongest clues are changes that create an alternate entry path, especially when they are uncommon for the affected environment or appear outside normal administration windows.

One useful distinction is whether the artefact is merely suspicious or actually functional. A scheduled task that launches a script from a temporary directory, a service that points to an unexpected binary, or a web shell placed in a web root all suggest the attacker has moved beyond opportunistic execution and is building a reusable foothold. If you can confirm the artefact survives a restart or reappears after removal, persistence is no longer theoretical.

Repeated use of PowerShell, WMI, MSHTA, rundll32, or similar execution paths matters because these tools often blend into ordinary administration. The question is not whether they are inherently malicious, but whether their use is aligned with the host role, the operator identity, and the surrounding process tree. When those details do not fit, the attacker is often trying to reduce visibility while keeping remote control.

What lateral movement looks like when the campaign expands

Lateral movement is the point where the intrusion stops being about one machine and starts becoming about access to the broader environment. At that stage, the actor is trying to find higher-value systems, reuse captured credentials, and reach infrastructure that can support escalation, collection, or disruptive action.

Repeated authentication attempts can be a clue to password spraying, credential replay, or brute-force attempts against internal systems. If those attempts are followed by successful logons from unusual source hosts, unusual hours, or accounts that do not normally authenticate that way, the campaign has likely entered a phase of account abuse and internal propagation.

Connections to domain controllers, administrative jump hosts, file servers, remote management services, or internal shell endpoints are especially important because they often signal the attacker is now navigating trust relationships rather than just running malware. MITRE ATT&CK Enterprise Matrix is useful here because it separates credential access, lateral movement, and privilege escalation into distinct adversary behaviours, which helps teams avoid treating every alert as a standalone endpoint issue.

Risk and Threat Considerations

Once an intrusion reaches persistence and lateral movement, the main risk changes from local compromise to environment-wide exposure. The attacker can often re-enter at will, harvest more credentials, and move toward systems that hold sensitive data, administrative control, or business-critical workflows.

Failure mechanism: The attacker turns one successful foothold into a repeatable access path, then uses internal trust, captured credentials, and remote administration paths to expand reach while blending into legitimate activity.

Impact: Containment becomes much harder, response cost rises sharply, and the likely outcome shifts toward broader credential compromise, privileged access abuse, data theft, or ransomware-style operational disruption.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0003 — PersistencePersistence is central to durable access after initial infection.
TA0008 — Lateral MovementThe question asks how to spot spread into internal systems.
Recommendation — Map observed persistence artefacts to TA0003 and scope surviving access paths. Map internal movement to TA0008 and hunt for pivot hosts and remote access use.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingAlerting depends on reviewing anomalous tasks, shells, and authentication patterns.
IA-5 — Authenticator ManagementRepeated authentication attempts and credential abuse are part of the progression.
AC-6 — Least PrivilegeLateral movement becomes more damaging when accounts can reach admin systems.
Recommendation — Use AU-6 to review anomalous execution and logon activity for intrusion expansion. Use IA-5 to rotate or revoke suspected credentials and reduce reuse opportunities. Use AC-6 to limit accounts from reaching high-value internal systems by default.

Practitioner Guidance

What to prioritise: Treat persistence and lateral movement as a containment problem, not just an endpoint cleanup problem. If you see new tasks, web shells, or repeated internal authentication activity, prioritise scoping for adjacent hosts, reusable credentials, and management-plane access before focusing on malware removal.

What to verify: Confirm whether the artefact can survive reboot, whether the account used for internal access is normal for that system, and whether the source host has touched other systems in the same time window. A single suspicious binary matters less than a pattern of repeatable access across multiple systems.

Practitioner takeaway: The decisive question is whether the attacker has gained durable access and internal reach, because once that happens, one compromised host is rarely the real boundary of the incident.

Identity Threat Detection and Response (ITDR) Guide

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org