Watch for web shells, unusual RDP, SMB, or FTP activity, account searches around privileged users, unexpected mailbox or management-group changes, and large data transfers from servers that normally should not move bulk volumes. These signals suggest the attacker is expanding control, collecting credentials, and preparing for follow-on destructive activity.
When access becomes active lateral movement
The shift from initial access to lateral movement is visible when the attacker stops behaving like a single compromised user and starts acting like an operator inside your environment. Web shells, remote administration over RDP or SMB, and unexpected FTP sessions often indicate interactive expansion, while credential hunting shows the attacker is trying to turn one foothold into broader reach.
That distinction matters because lateral movement is usually a transition point, not the end state. At that stage, the intruder is often mapping trust relationships, testing which systems can be reached, and looking for credentials that unlock higher-value zones.
Signals tend to cluster. A single anomalous logon may be noise, but repeated use of privileged admin paths, unusual service-to-service access, and changes in access patterns around management systems suggest the attacker is actively extending control rather than merely persisting.
What credential hunting looks like in practice
Credential hunting is rarely a single event. It often shows up as account discovery around privileged users, mailbox access that is out of pattern, authentication attempts against administrative interfaces, and attempts to read or copy secrets from servers, scripts, or configuration stores.
Large data transfers from systems that do not normally move bulk volumes are especially important when they coincide with new access paths. In many intrusions, collection is paired with scanning for reusable credentials, session tokens, or management access that can be reused elsewhere in the estate.
The practical question is whether the behaviour is consistent with normal administration. If the activity is not explained by a change window, support task, backup job, or scheduled automation, treat it as a potential sign that the attacker is preparing for privilege escalation, persistence, or downstream destructive action.
Which surrounding changes make the warning stronger
The strongest indicator is not any one artifact, but the combination of access expansion, authentication abuse, and control-plane tampering. Unexpected changes in mailbox rules, management-group membership, or privileged group assignments can show that the intruder is reshaping the environment to preserve access after the first entry point is closed.
That is why defenders should read these signs as a sequence. Initial access is often the quiet phase; lateral movement and credential hunting are the phase where the attack becomes operationally dangerous because the attacker can pivot, escalate, and set up follow-on actions across multiple systems.
Risk and Threat Considerations
Once lateral movement begins, the risk changes from one compromised host or account to a broader trust failure. The attacker can reuse discovered credentials, abuse administrative protocols, and reach systems that were never meant to be directly exposed from the original foothold.
Failure mechanism: Reused credentials, weak segmentation, and excessive trust in internal administration channels let the attacker move laterally, collect more credentials, and widen access without needing repeated exploitation.
Impact: The intrusion can progress from contained access to domain-wide compromise, mailbox takeover, secret theft, ransomware staging, or destructive action against management and backup systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1021 — Remote Services | Lateral movement commonly uses RDP, SMB, and FTP-style remote access. |
| T1087 — Account Discovery | Credential hunting often includes searching for privileged users and accounts. | |
| T1003 — OS Credential Dumping | Credential hunting often escalates into theft of reusable secrets from systems. | |
| Recommendation — Map remote-service activity to T1021 and hunt for cross-host pivoting. Hunt for account discovery activity around privileged identities and admin groups. Prioritise detection of credential dumping and secret access across servers. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | These signs are identified by correlating unusual access and transfer telemetry. |
| AC-6 — Least Privilege | Privilege abuse and overbroad access are central to lateral movement and credential hunting. | |
| Recommendation — Correlate audit records to distinguish administration from lateral movement. Reduce reachable privilege paths to limit lateral movement opportunities. | ||
Practitioner Guidance
What to prioritise: Correlate remote access logs, privileged account activity, mailbox or directory changes, and server transfer volumes around the same time window. A single alert is less useful than a pattern that shows access, discovery, and expansion in sequence.
What to verify: Separate legitimate administration from hostile activity by checking change tickets, scheduled maintenance, known jump hosts, and expected automation. If those explanations do not hold, assume the actor is probing for privilege and reach, not just maintaining persistence.
Practitioner takeaway: The key judgement is whether the activity is still confined to one entry point or has started to behave like an operator mapping, collecting, and reusing trust. Once that shift is visible, treat the incident as an environment-wide containment problem, not a host-level investigation.
Related resources from NHI Mgmt Group
- Why does credential theft on compromised macOS systems increase the risk of lateral movement and external access?
- What are the signs that a ransomware intrusion is moving from access to active encryption?
- What is the difference between initial access and lateral movement in an AI-enabled intrusion?
- What are the signs that an intruder is moving from initial access into lateral movement on enterprise networks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org