Free tools Windows power users keep installed
One-click scans. No signup required.
Silverfort’s LATMA (Lateral Movement Analyzer) is a free, open-source tool that collects Active Directory and Azure AD authentication data, then analyzes how accounts and computers connect to identify suspicious lateral movement. Its workflow combines Windows-based log collection, a learning period, graph analysis, and reports that include an interactive timeline and a GIF.
What LATMA does
Silverfort announced LATMA on September 28, 2023, as a tool with two components: a Logs Collector and an Analyzer. The collector gathers authentication activity; the analyzer looks for suspicious movement, describes who performed it and when, and visualizes activity. The project README documents collection from domain and Azure AD environments, with the collector running on Windows and the analyzer available for Windows or Linux. Silverfort’s announcement and the LATMA GitHub repository describe the project.
How LATMA detects possible lateral movement
1. Collect authentication activity
The collector scans domain controllers for successful NTLM event 8004 logs, endpoints for successful Kerberos event 4648 logs, and Azure AD sign-ins. The resulting data includes source host, destination, username, authentication type, SPN, and timestamp. The collection scope is therefore based on the documented log sources; the README does not establish universal coverage of every cloud identity service or authentication path.
2. Learn normal activity
LATMA has a three-week learning period during which it does not alert. Learning continues afterward. It uses familiar account-and-machine pairs and identifies benign sinks and hubs so routine authentication traffic can be filtered from the graph. That initial period is an operational consideration: detections should not be expected during the first three weeks.
#1 Best Overall
3. Build and analyze a graph
LATMA represents computers as nodes and authentications as directed edges, with protocol, date, and account attributes. Silverfort’s announcement describes broad search, advance, and act behavior patterns. The README names specific indicators: White Cane, Bridge, Switched Bridge, Weight Shift, and Blast. These patterns provide context for how movement unfolds across connected machines rather than treating every authentication as an isolated event.
4. Review alerts and outputs
Silverfort says LATMA generates an alert when at least two suspicious pattern types occur in sequence. Its outputs include all_authentications.csv, propagation.csv, a GIF showing progression, and an interactive, color-coded timeline. Those artifacts can help an analyst inspect the activity and its order, but they do not replace investigation of whether a sequence is malicious.
Requirements and deployment considerations
The README says collection requires LDAP or LDAPS and RPC connectivity, as well as domain-admin, Event Log Reader, or equivalent permissions. In practice, deployment depends on the organization having the relevant audit data enabled and accessible across the systems in scope. Check access and connectivity to domain controllers and endpoints before treating an incomplete dataset as evidence that no movement occurred. Consult the repository README for project instructions and current implementation details.
- Collector operating system: Windows.
- Analyzer operating systems: Windows or Linux.
- Documented telemetry: successful NTLM event 8004, successful Kerberos event 4648, and Azure AD sign-ins.
- Permissions and connectivity: LDAP/LDAPS and RPC, plus domain-admin, Event Log Reader, or equivalent access.
- Alerting behavior: no alerts during the three-week learning period; learning continues thereafter.
Does LATMA support Azure AD and hybrid environments?
Yes, the current README documents Azure AD sign-in collection alongside on-premises Active Directory authentication logs, and describes detection within AD or between cloud and on-premises systems. This supports a hybrid collection use case where the required data and access are available. It should not be read as a claim that LATMA covers all cloud identity providers, services, or sign-in types. Silverfort’s 2023 announcement framed cloud and cross-platform detection as potential future enhancement work; the README’s documented Azure AD collection is the more specific evidence for the present scope.
Recommended Free Tools
Rank #3
What the published detection figures mean
Silverfort reported that it ran LATMA on dozens of datasets and detected 95% of lateral movements. The same 2023 vendor report gave a false-alarm frequency of approximately once every three days and compared LATMA with other algorithms. These are vendor-reported results, not an independent benchmark; the published figures should not be treated as a guarantee of detection or a prediction of alert volume in another environment. The repository’s prerequisites and three-week learning period also affect how a deployment can be evaluated. See Silverfort’s announcement and reported results.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is there an Amazon product to buy?
No. LATMA is free, open-source software, so a physical Amazon product is not required to use it. The software and setup information are available from the LATMA repository. Silverfort also offers a commercial Identity Security Platform, but that is a separate enterprise product rather than a purchase prerequisite for LATMA.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

