Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR047
  • Created: 22nd July 2026
  • Updated: 22nd July 2026
  • Platforms: MacOSWindowsLinuxOracle Cloud Infrastructure (OCI)Google Cloud Platform (GCP)Microsoft AzureAmazon Web Services (AWS)
  • MITRE ATT&CK®: TA0008T1021T1021.001T1021.002T1021.003T1021.004T1021.005T1021.006T1021.007T1021.008T1210T1563T1563.001T1563.002T1072T1550T1550.001T1550.002T1550.003T1550.004T1047
  • Contributor: The ITM Team

Lateral Movement

The subject accesses, connects to, or obtains the ability to execute actions on an additional organizational system beyond their current operating context. Destination systems may include servers, jump hosts, administrative workstations, cloud workloads, network devices, employee endpoints, or other systems reachable through organizational infrastructure.

 

Lateral movement may involve access that is technically authorized but inconsistent with the subject’s role, normal working pattern, or immediate business requirement. It may also involve unauthorized access obtained through another account, a remote service, an existing session, alternate authentication material, a centralized management platform, or exploitation of a vulnerable service.

 

This behavior is preparatory where movement to the destination system expands the subject’s reach, places them closer to sensitive data or functionality, or enables a later infringement.

Subsections (5)

ID Name Description
PR047.003Centralized Management Platform Access

The subject uses a cloud control plane, software deployment system, endpoint-management platform, configuration-management service, or orchestration tool to access, manage, or execute actions on additional organizational systems outside an approved operational requirement.

PR047.005Exploitation of Remote Services

The subject exploits a vulnerability in a network-accessible service, application, management interface, operating-system component, or hypervisor to obtain unauthorized access or execution capability on an additional organizational system.

 

This object applies as Preparation where exploitation is used to reach or establish an operating position on a destination system before a later infringement. Where the exploitation itself causes the principal harm, disruption, or unauthorized modification, investigators should also apply the relevant Infringement section.

PR047.002Remote Administrative Services

The subject uses a network-accessible administrative service or operating-system management interface to access resources, transfer content, execute commands, or perform actions on an additional organizational system without establishing an ordinary interactive desktop session.

 

Methods may include Server Message Block (SMB), Windows administrative shares, Distributed Component Object Model (DCOM), Windows Remote Management (WinRM), or remote Windows Management Instrumentation (WMI).

PR047.001Remote Interactive Access

The subject establishes an interactive command-line, graphical, or cloud-native session with an additional organizational system. The subject may use Remote Desktop Protocol, Secure Shell, Virtual Network Computing, a cloud virtual-machine console, or an equivalent service to operate the destination system.

PR047.004Remote Session Hijacking

The subject takes control of an existing authenticated remote service session to operate an additional organizational system under the identity and access context of the session owner. The subject may hijack an active or disconnected RDP session, reuse an SSH agent or socket, or otherwise attach to a pre-existing remote session without completing a new authentication process.