Back

Episode 42: Detecting Lateral Movement in Hybrid Cloud Environments

TL;DR

Nearly 90% of organizations had a lateral movement incident in the past year, and 96% of that movement never triggers an alert in a traditional security tool. This episode explains why hybrid cloud, on-premises Active Directory synced to a cloud identity provider, workloads spread across multiple clouds, makes this phase of an attack so hard to see, and what it actually takes to detect it: behavioral analytics, identity correlation, coverage for unmanaged devices, and a security operations center that can act on what it finds.

Episode notes

Adam

Okay, quick numbers to open with. Almost nine out of ten organizations had a security incident involving lateral movement in the past year. And of all that movement, ninety six percent of it never triggered a single alert in a traditional security tool.

Christina

Say that second number again, because it's the one that should worry people.

Adam

Ninety six percent. Not caught, not flagged, nothing. The attacker was just moving through the environment and the tools watching that environment had no idea.

Christina

So let's define the term first, for anyone who hasn't run into it. What is lateral movement, exactly?

Adam

It's the phase of an attack that happens after somebody's already gotten past the perimeter. They're in. And instead of doing something loud, they start quietly moving from system to system, using credentials and tools that are already there. Not malware, not some obvious hacking tool. Just an admin login, a native protocol, a script that's supposed to be there anyway.

Christina

Which is exactly why it's so hard to catch. It looks like normal activity, because in a sense, it is normal activity, just being used by the wrong person.

Adam

Exactly. And it gets a lot harder again once you're in a hybrid environment, which is basically everyone at this point. On-premises Active Directory, a cloud identity provider like Microsoft Entra ID, workloads spread across AWS, Azure, and a private data center all at the same time.

Christina

So walk me through why hybrid specifically makes this worse, rather than just adding more places to look.

Adam

Because those environments aren't really separate, they're bridged. There's a synchronization server, usually running a tool called Microsoft Entra Connect, that links on-premises Active Directory to the cloud identity side. And that one server is about as privileged as it gets. It holds credentials that can read and write to both environments at once.

Christina

So if an attacker gets that one server.

Adam

They get both worlds. They can forge identity tokens that are trusted across the whole environment, add a malicious domain to the tenant, or escalate privileges on both sides, without touching anything that looks like a traditional hacking tool. There's actually a formal name for a couple of these techniques in the MITRE ATT&CK framework, a public catalog of attacker behavior that security teams use as a shared reference. Cloud Accounts and Cloud Services are the specific tactics, and the reason they're hard to catch is that the login events themselves look completely legitimate to any tool that's only watching one side of the bridge.

Christina

Okay, so that's the identity half of the problem. What's the other half?

Adam

Network visibility. Most security tools, firewalls, intrusion detection systems, web gateways, were built to watch traffic crossing the perimeter, coming in and going out. That's called north-south traffic. They were never built to watch traffic moving sideways, between internal systems. That's east-west traffic, and it's basically a blind spot by design for most of these tools.

Christina

And in a hybrid environment, east-west traffic is everywhere. On-premises servers talking to cloud workloads, virtual machines talking to each other inside the same cloud network, containers talking to containers.

Adam

All of it invisible to a firewall that's only watching the front door. And endpoint detection tools don't fully solve this either. They see some of that traffic from the point of view of one managed device, but they don't see both sides of a connection at once, and they don't cover anything that isn't a managed endpoint in the first place.

Christina

Which is a real gap. There's a stat on that too, isn't there?

Adam

There is. Close to forty percent of east-west traffic in hybrid environments doesn't have enough context attached to it for a security team to confidently investigate, according to Illumio's research. Teams are technically monitoring. They're just not actually seeing.

Christina

And I imagine that turns into an alert fatigue problem pretty fast.

Adam

It does, and it's a big one. The same research found that two thirds of security teams get more alerts than they can actually investigate, averaging over two thousand alerts a day. When you can't tell signal from noise at that volume, lateral movement just has time to keep progressing. The average time to detect an issue that came from a missed alert is over twelve hours. That's more than enough time for an attacker to go from a single foothold to full domain controller access.

Christina

So given all of that, how does enhanced.io actually approach detecting this?

Adam

Four layers, and they all work together rather than separately. First, east-west network monitoring. We pull in flow data from across the whole hybrid environment, cloud flow logs, on-premises network taps, workload traffic metadata, and baseline what normal looks like for every device, subnet, and workload. So when a workload suddenly starts talking to systems it's never touched before, that gets flagged.

Christina

Behavioral, not signature based.

Adam

Has to be. An attacker using a valid login and a built-in tool doesn't leave a signature to match against. Second layer, identity and authentication correlation. Because that identity bridge we talked about is the single highest value target in a hybrid environment, we treat identity telemetry as just as important as network telemetry. Things like a directory synchronization account being read outside its normal schedule, or a high privilege cloud role being assumed without multi-factor authentication, or a Kerberoasting pattern, which is basically an attacker harvesting service account credentials through a specific type of ticket request.

Christina

And presumably the same suspicious behavior means different things depending on what it's touching.

Adam

Exactly right. The same technique against a developer's laptop and against a domain controller sitting next to a financial database gets a completely different severity rating, because the risk is completely different.

Christina

What's the third layer?

Adam

Coverage for unmanaged devices. IoT sensors, meaning internet of things devices like sensors and smart equipment, operational technology systems, sometimes called OT, and older infrastructure that just can't run an endpoint agent at all. These are invisible to anything that's endpoint centric, and attackers know it, so they use them as pivot points on purpose. We extend visibility to those non-agent surfaces through network level telemetry and integrations built specifically for that kind of equipment.

Christina

And the fourth?

Adam

Cross-environment correlation, which is really the layer that ties the other three together. A slightly unusual ticket request on-premises doesn't mean much on its own. Pair it with an unusual role assumption in the cloud twenty minutes later, and suddenly it's an obvious pattern. That correlation across on-premises logs, cloud audit trails, identity events, and network telemetry is what turns a pile of alerts into one coherent incident.

Christina

Okay, so you've detected it. What actually happens next? Because detection on its own doesn't stop anything.

Adam

Right, detection without response is just a dashboard. This is where the twenty four seven security operations center comes in, and it runs in three phases. First, triage and confirmation, an analyst checks the correlated alert against behavioral baselines and rules out false positives. That step matters more than people think, security teams lose an average of fourteen hours a week chasing false alarms, so context-rich alerts save real analyst time.

Christina

And then?

Adam

Isolation and containment. Once it's confirmed, we act immediately, suspending accounts, enforcing network segmentation, isolating an endpoint, or revoking cloud identity tokens, depending on exactly what technique is in play. The goal is simple, stop the attacker before they reach anything that actually matters. And third, remediation and hardening, closing whatever let them in in the first place. Credential rotation, tightening a policy, updating segmentation rules. The Fractional Security Director assigned to every partner plays a real role here too, turning what's technically true into guidance an MSP can actually act on.

Christina

Why does the twenty four seven part matter specifically for this kind of attack, rather than security in general?

Adam

Because lateral movement doesn't wait for business hours. Attackers often start this exact phase at night or over a weekend, on purpose, because they know security teams are thinnest right then. A detection that fires at two in the morning on a Saturday is worthless if nobody's there to act on it.

Christina

So walk me through why this actually matters for MSPs specifically, not just as a technical problem but as a business one.

Adam

Because every client has a different hybrid setup, different tools, different risk profile, and delivering this consistently across dozens or hundreds of environments is genuinely hard to do alone. The advantage of enhanced.io here is that it plugs into whatever's already there, over four hundred integrations, so an MSP isn't asking a client to rip out their existing stack to get this visibility.

Christina

And I know there's a compliance angle too.

Adam

There is, and it's not a minor one. Lateral movement incidents aren't just operational events anymore, they're compliance events. Frameworks like the NIST cybersecurity guidance for federal contractors, CMMC, NIS2, and DORA all require MSPs to demonstrate an actual incident response capability, not just detection tooling sitting on a shelf. Reporting mapped to those frameworks is built into the platform, so that documentation comes out the other side without a separate manual process.

Christina

So if I'm pulling all of this together, what's the actual takeaway for someone listening?

Adam

The honest takeaway is that more tools isn't the answer here. It's the right architecture. You need continuous east-west visibility, identity telemetry correlated across on-premises and cloud, coverage for the unmanaged devices everyone forgets about, and enough analyst capacity to actually act before an attacker reaches something that matters.

Christina

Which is really the whole model over at enhanced.io. Full spectrum detection across endpoint, network, cloud, identity, and IoT and OT, with a twenty four seven security operations center behind it, built specifically for MSPs, never sold direct to end clients.

Adam

That's it exactly. Ninety percent of organizations have already been through this. The only real question left is whether anyone would have known.