detect-lateral-movement
Installation
SKILL.md
detect-lateral-movement
Attack pattern
The canonical cloud lateral-movement sequence after initial access:
- Attacker compromises an IAM principal (stolen access key, compromised EC2 instance profile, phished human)
- Attacker pivots identity with a privileged cloud API operation:
- AWS
AssumeRole* - GCP service-account impersonation / key generation
- Azure role assignment / access elevation / managed-identity assignment
- Azure Entra / Microsoft Graph application or service-principal credential changes
- AWS
- From a compute resource inside the cloud network, attacker initiates east-west traffic to an internal service the original principal never accessed
- Data transfer starts
Audit logs alone see step 2. Flow logs alone see steps 3–4. Neither source alone tells you the story — the API call may look routine and the flow may look like ordinary internal traffic. The join is where the detection lives.
This skill correlates them.