What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Detect lateral movement by correlating endpoint, identity, and network activity against the access your organization expects. Stop it by reducing unnecessary paths between systems, then containing affected devices or accounts with the narrowest action that limits further access without disrupting essential services.

What is lateral movement?

CISA defines lateral movement as “the process of pivoting from host to host or from one user account to another to reposition, supplement, or spread the active foothold.” In practice, an attacker who has gained access to one device or account may use it to reach other systems, applications, or identities.

That makes lateral movement a pattern to investigate, not a single event or alert. A remote connection, an unusual sign-in, or access to a sensitive application can be legitimate on its own. The stronger lead is a combination of activity that is unexpected for that identity, device, destination, or time.

How do I detect lateral movement in my network?

Map expected access before setting alerts

List sensitive systems, network segments, privileged identities, administrative routes, remote-access paths, service accounts, and operational exceptions. Record which identities and systems should communicate, and for what business purpose. This gives analysts a baseline for judging whether a connection is unusual without treating every uncommon event as malicious.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

Collect evidence from three layers

Evidence source Useful records What it can help establish
Endpoint Process, logon, and network-connection activity; unexpected remote connections Which host initiated or received a connection and what activity preceded it. CISA’s ransomware guidance notes that endpoint detection and response (EDR) can provide host-specific context for lateral connections.
Identity Sign-ins, audit events, privilege changes, unusual account use, and risky sign-ins Which account accessed a resource, whether its privileges changed, and whether the sign-in merits scrutiny.
Network Allowed and denied inter-segment traffic, flows to sensitive application segments, and traffic through gateways Which paths were used or attempted, including activity crossing boundaries between segments.

CISA recommends collecting access and security-focused logs for detection and response. Centralize relevant records and retain them according to your investigation needs and applicable legal requirements; the cited guidance does not establish one retention period suitable for every organization.

Correlate activity into an investigation lead

When an alert appears, connect the identity event to the endpoint and destination: identify the account, the device it used, the resource it reached, and the sequence of related events. Check whether the access fits the asset map, the account’s role, and known service or administrative activity. A single signal may be benign; a sequence that crosses expected boundaries warrants closer investigation.

Rank #2
Wintertion1U/Desktop/Rackmount Firewall Hardware,OPNsense, VPN, Network Security Appliance, Router PCN2600 D2700, 4 x Gigabit LAN, COM, VGA, Fan, 0 RAM, 0 Storage (Desktop Type, 4G RAM 64G SSD)
  • equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
  • Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
  • 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
  • Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
  • There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product

Tune anomaly rules to local behavior

Microsoft’s Global Secure Access operations guide gives a product-specific sample for flagging a user who accesses more than 10 distinct private application segments within 15 minutes. The guide recommends calculating a local baseline from recent activity and adjusting the threshold when normal use is higher or lower. Treat that value as an example to validate against the tenant’s data schema, service identities, and expected application use—not as a universal indicator of compromise.

Other useful leads include access to a sensitive application by a risky identity or activity from an unmanaged device. Microsoft advises validating such signals with application and device owners before classifying them as unauthorized.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

How do I stop an attacker moving between computers?

Reduce unnecessary reachability

Separate resources by sensitivity or function, and allow cross-segment communication only where a business function requires it. This limits the systems reachable after a host or credential is compromised. CISA’s joint living-off-the-land guidance also recommends monitoring inter-segment traffic and placing sensors at useful network intersections, including segment boundaries and gateways.

Network metadata tools such as Zeek, and network intrusion detection systems such as Snort and Suricata, are examples named in CISA’s guidance. They can contribute visibility; no one tool should be assumed to identify every form of lateral movement.

Rank #4
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Constrain privileged access

Review administrative paths and access to sensitive systems alongside ordinary segment rules. Remove access that has no current business need, and account for service identities and documented operational exceptions so controls do not silently break legitimate functions. Revisit the map when systems, responsibilities, or workflows change.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Should I isolate a compromised device?

Isolation can limit a device’s ability to contact other systems, but the right action depends on the device’s role and the isolation method available. Consider the likely impact on business operations, investigation access, and essential connectivity before acting. Avoid casually isolating network infrastructure that provides critical connectivity; use your incident plan to assess a safer, effective scope.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft documents an endpoint isolation action that disconnects an affected device while maintaining a connection to its Defender service for monitoring. Supported platforms, selective-isolation options, VPN behavior, and enrollment requirements vary by configuration. The documentation also describes containment actions for devices, IPs, and users under specific conditions; some actions can affect connectivity or trigger domain policy synchronization. Check current product documentation and local procedures before using a product-specific action.

What should the response sequence be?

  1. Confirm and scope. Compare the alert with endpoint, identity, and network evidence. Identify likely affected assets, accounts, destinations, and time range.
  2. Contain narrowly. Restrict the compromised endpoint or identity using the least disruptive action likely to stop further access. Preserve essential business functions and investigation channels where possible.
  3. Investigate adjacent activity. Review related systems and accounts for similar access, privilege changes, or connections. Preserve relevant logs and evidence, and restrict compromised access as appropriate.
  4. Remediate the cause. Remove persistence and address the weakness or access path that enabled the foothold. Follow the organization’s incident plan and applicable regulatory or contractual obligations.
  5. Validate and restore. Confirm that abnormal movement has stopped, then release restrictions and restore normal access under change control.

This sequence is a general operational approach, not a vendor-specific playbook. NIST SP 800-61 Rev. 3 provides broader incident-response framing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.