Detecting Lateral Network Movement / Spread in EventSentry
How to detect lateral movement on a network in real time with EventSentry, based on the example of a process spreading.
With the proper auditing enabled (Logon/Logoff – Logon (Failure)) and EventSentry installed however, we can permanently block remote users / hosts who attempt to log on too many times with a wrong password. Setting this up is surprisingly simple.