Lateral Movement Detection
Off-host pivot detection. RDP, SMB, WMI and WinRM lateral patterns — contain the spread before encryption or staging fires.
What this playbook does
Lateral Movement Detection guides the responder from the initial signal through containment, evidence capture and verifiable close. Each step records who did what and when, so the work finishes with an audit trail you can hand to a regulator, an insurer, or your own board.
Cyber Toolbox does not detect the event — it assumes your monitoring tools, an external alert or a phone call already surfaced it. Once you have the signal, this playbook is the structured response: pick it, walk it across the affected assets, and promote it to a managed case the moment it earns one.
This is a Community playbook — free to walk against your own assets on every plan, including the free tier.
When you open it
A response is created in the app, linking the asset you're working to this playbook. The walker takes you step by step — you capture the inputs each step asks for (logs pulled, screenshots, decisions made), promote to a case if it earns one, and close with a defensible record you can export.
Cyber Toolbox launches 31 July 2026.
Get a heads-up the moment Community opens — free for a single operator.
At a glance
- Lifecycle
- Incident response
- Code
- PB-CIRP-108
- Category
- Enterprise IT
- ATT&CK techniques
- 6
- Tier
- Community (free)
Every playbook carries the methodology on rails — structured phases, severity rules, decision points and evidence capture. The tier sets where it unlocks, not how it walks.