Detecting Lateral Movement with SMB and WinRM Telemetry
Lateral movement is the point where an intrusion turns into a breach. Two of the most common Windows pathways are SMB (port 445) and WinRM (ports 5985 and 5986). If you can monitor how these protoc...