Incident Analysis: Lateral Movement
In this hands-on lab, you will learn how to analyze common lateral movement mechanisms during an incident response engagement.

Course Content
Upon completing this lab, you should be able to:
- List and describe selected common methods of Lateral Movement associated with Windows environments.
- Develop and test hypotheses relevant to Lateral Movement observations.
- Review common methods Lateral Movement associated with Windows.
- Describe how generic analytical methods can be applied to the examination of Lateral Movement activity.
- Examine example evidence related to the Lateral Movement technique T1021.001 Remote Services: Remote Desktop Protocol.
- Document different Lateral Movement findings.













