IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: Can Lateral Movement activities be detected?

EDR: Can Lateral Movement activities be detected?

Environment

  • EDR (formerly Carbon Black Response): All supported versions

Question

Can Lateral Movement activities be detected with existing threat reports?

Answer

Yes, the "Lateral Movement - File Write to SMB Admin Shares" report has been added to the Bit9EndpointVisibility and Bit9AdvancedThreats feeds.

Additional Notes

If assistance is required to create custom watchlists or to modify the existing "Lateral Movement - File Write to SMB Admin Shares" report to suit the environment, options are
  • Post questions in the Threat Research space in the UEX
  • Request Professional Services with the help of CSM.

Related Content


Labels (2)
Tags (3)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎01-19-2021
Views:
1182
Contributors