A security analyst is investigating a compromised workstation. The attacker gained initial access, established persistence, and then attempted to move laterally to other systems. The analyst wants to understand the full scope of the lateral movement attempts and identify all accessed systems. Which of the following forensic artifacts would provide the MOST comprehensive evidence of lateral movement on the compromised workstation?
- ASecurity Event Logs (4624, 4648, 4672) and network connection logs.
- BPrefetch files and Amcache.hve.
- CRegistry hives (NTUSER.DAT, SYSTEM) and shellbags.
- DBrowser history and download logs.
Show answer & explanationAnswer & explanation
Correct answer: A. Security Event Logs (4624, 4648, 4672) and network connection logs.
Lateral movement involves authentication to and execution on other systems. Windows Security Event Logs, particularly Event IDs 4624 (successful login), 4648 (a logon was attempted using explicit credentials), and 4672 (admin logon) provide direct evidence of authentication attempts from the compromised host to other systems. Correlating these with network connection logs (e.g., firewall, flow data) would show the actual network communication paths, offering the most comprehensive view of lateral movement.
Why the other options are wrong
- B. Prefetch files and Amcache.hve indicate program execution on the *local* system, not necessarily lateral movement to *other* systems.
- C. Registry hives and shellbags provide evidence of user activity and installed software on the local system, but not direct evidence of authentication or network connections to *other* systems for lateral movement.
- D. Browser history and download logs primarily indicate web activity and initial compromise, not lateral movement within the network.
Lateral Movement Forensics
The process of identifying and analyzing forensic artifacts that indicate an attacker's attempts to move from an initially compromised system to other systems within a network, often involving credential use and remote execution.
- Looks for signs of authentication to other hosts.
- Examines network connections and remote command execution.
- Key artifacts include logon events, network flows, and remote service logs.
Memory trick: To see where they went, check their logins and network trails.