detect-lateral-movement

Installation
SKILL.md

detect-lateral-movement

Attack pattern

The canonical cloud lateral-movement sequence after initial access:

  1. Attacker compromises an IAM principal (stolen access key, compromised EC2 instance profile, phished human)
  2. Attacker pivots identity with a privileged cloud API operation:
    • AWS AssumeRole*
    • GCP service-account impersonation / key generation
    • Azure role assignment / access elevation / managed-identity assignment
    • Azure Entra / Microsoft Graph application or service-principal credential changes
  3. From a compute resource inside the cloud network, attacker initiates east-west traffic to an internal service the original principal never accessed
  4. Data transfer starts

Audit logs alone see step 2. Flow logs alone see steps 3–4. Neither source alone tells you the story — the API call may look routine and the flow may look like ordinary internal traffic. The join is where the detection lives.

This skill correlates them.

Installs
3
GitHub Stars
3
First Seen
Apr 20, 2026
detect-lateral-movement — msaad00/cloud-ai-security-skills