Preparation
Account Creation
Account Discovery
AI-Assisted Capability Development
Archive Data
Authorization Token Staging
Boot Order Manipulation
CCTV Enumeration
Circumventing Security Controls
- Bypassing Network Segmentation
- Downgrading Microsoft Information Protection (MIP) labels
- Impairing a Security Agent
- Impairing an Anti-Virus Solution
- Modifying a Cloud-Based Firewall
- Modifying a Host-Based Firewall
- Modifying a Network-Based Firewall
- Unauthorized Manipulation of Anti-Virus Exclusions
- Uninstalling a Security Agent
- Uninstalling an Anti-Virus Solution
Credential Collection
Data Deobfuscation
Data Obfuscation
Data Staging
Delegated Preparation via Artificial Intelligence Agents
Device Mounting
Email Collection
External Media Formatting
File Download
File Exploration
Hardware-Based Remote Access (IP-KVM)
Impersonation
IT Ticketing System Exploration
Joiner
Lateral Movement
Media Capture via External Device
Mover
Network Scanning
Observational Information Gathering
On-Screen Data Collection
Oversight Circumvention and Control Degradation
Persistent Access via Bots
Physical Disk Removal
Physical Exploration
Physical Item Smuggling
Private / Incognito Browsing
Privilege Elevation
Read Windows Registry
Remote Desktop (RDP)
Security Software Enumeration
Social Engineering (Outbound)
Software Installation
- Installation of Dark Web-Capable Browsers
- Installing Browser Extensions
- Installing Browsers
- Installing Cloud Storage Applications
- Installing FTP Clients
- Installing Messenger Applications
- Installing Note-Taking Applications
- Installing RDP Clients
- Installing Screen Sharing Software
- Installing SSH Clients
- Installing Virtual Machines
- Installing VPN Applications
Software or Access Request
Suspicious Web Browsing
System Persistence
System Profiling
Testing Ability to Print
Testing Security Controls
Unauthorized Hardware Introduction
VPN Usage
- ID: PR047
- Created: 22nd July 2026
- Updated: 22nd July 2026
- Platforms: MacOSWindowsLinuxOracle Cloud Infrastructure (OCI)Google Cloud Platform (GCP)Microsoft AzureAmazon Web Services (AWS)
- MITRE ATT&CK®: TA0008T1021T1021.001T1021.002T1021.003T1021.004T1021.005T1021.006T1021.007T1021.008T1210T1563T1563.001T1563.002T1072T1550T1550.001T1550.002T1550.003T1550.004T1047
- Contributor: The ITM Team
Lateral Movement
The subject accesses, connects to, or obtains the ability to execute actions on an additional organizational system beyond their current operating context. Destination systems may include servers, jump hosts, administrative workstations, cloud workloads, network devices, employee endpoints, or other systems reachable through organizational infrastructure.
Lateral movement may involve access that is technically authorized but inconsistent with the subject’s role, normal working pattern, or immediate business requirement. It may also involve unauthorized access obtained through another account, a remote service, an existing session, alternate authentication material, a centralized management platform, or exploitation of a vulnerable service.
This behavior is preparatory where movement to the destination system expands the subject’s reach, places them closer to sensitive data or functionality, or enables a later infringement.
Subsections (5)
| ID | Name | Description |
|---|---|---|
| PR047.003 | Centralized Management Platform Access | The subject uses a cloud control plane, software deployment system, endpoint-management platform, configuration-management service, or orchestration tool to access, manage, or execute actions on additional organizational systems outside an approved operational requirement. |
| PR047.005 | Exploitation of Remote Services | The subject exploits a vulnerability in a network-accessible service, application, management interface, operating-system component, or hypervisor to obtain unauthorized access or execution capability on an additional organizational system.
This object applies as Preparation where exploitation is used to reach or establish an operating position on a destination system before a later infringement. Where the exploitation itself causes the principal harm, disruption, or unauthorized modification, investigators should also apply the relevant Infringement section. |
| PR047.002 | Remote Administrative Services | The subject uses a network-accessible administrative service or operating-system management interface to access resources, transfer content, execute commands, or perform actions on an additional organizational system without establishing an ordinary interactive desktop session.
Methods may include Server Message Block (SMB), Windows administrative shares, Distributed Component Object Model (DCOM), Windows Remote Management (WinRM), or remote Windows Management Instrumentation (WMI). |
| PR047.001 | Remote Interactive Access | The subject establishes an interactive command-line, graphical, or cloud-native session with an additional organizational system. The subject may use Remote Desktop Protocol, Secure Shell, Virtual Network Computing, a cloud virtual-machine console, or an equivalent service to operate the destination system. |
| PR047.004 | Remote Session Hijacking | The subject takes control of an existing authenticated remote service session to operate an additional organizational system under the identity and access context of the session owner. The subject may hijack an active or disconnected RDP session, reuse an SSH agent or socket, or otherwise attach to a pre-existing remote session without completing a new authentication process. |
Preventions (7)
Detections (6)
MITRE ATT&CK® Mapping (21)
ATT&CK Enterprise Matrix Version 19.1