{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/esql/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["lateral-movement","threat-detection","esql","detection-engineering"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis detection rule provides a higher-order analytical approach to identify lateral movement by correlating disparate security alerts across an enterprise network. Instead of focusing on single atomic events, the rule logic aggregates alerts where the \u003ccode\u003ehost.ip\u003c/code\u003e of one host correlates with the \u003ccode\u003esource.ip\u003c/code\u003e of alerts originating from a separate host. This pattern suggests an adversary is using a compromised endpoint as a pivot point to conduct further reconnaissance or access additional systems within the environment. The rule filters out low-severity events and specific noise-prone alerts to maintain a high signal-to-noise ratio, effectively acting as an automated threat hunting mechanism to surface cross-host infection chains.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful lateral movement allows adversaries to navigate an internal network, elevate privileges, and reach high-value assets such as domain controllers, sensitive file shares, or cloud service configuration interfaces. If left undetected, this phase of an attack often precedes ransomware deployment, large-scale data exfiltration, or long-term persistence in the target network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and response teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the higher-order detection logic to identify cross-host alert correlation patterns indicating potential pivots.\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003ehost.ip\u003c/code\u003e collection for all endpoints, specifically ensuring Elastic Defend versions 8.18 and above are configured to populate this field as required for the logic.\u003c/li\u003e\n\u003cli\u003eReview the list of triggered alerts to isolate the patient-zero host; perform network isolation immediately upon confirming lateral movement indicators.\u003c/li\u003e\n\u003cli\u003eInvestigate the specific user accounts associated with the source and destination alerts to determine if credentials were compromised or if non-interactive service accounts are being abused.\u003c/li\u003e\n\u003cli\u003eTune the detection logic to account for known network architecture artifacts, such as NAT gateways, proxies, or jump hosts, which may generate frequent cross-host alert patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:19:34Z","date_published":"2026-09-18T19:19:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lateral-movement-detection/","summary":"This detection capability monitors for lateral movement by identifying sequences where a host IP address from one security alert subsequently appears as the source IP in alerts from a different host.","title":"Detection of Potential Lateral Movement via Alert Correlation","url":"https://feed.craftedsignal.io/briefs/2026-09-lateral-movement-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - Esql","version":"https://jsonfeed.org/version/1.1"}