Lateral Movement Alerts from a Newly Observed User

This rule detects multiple lateral movement alerts from a user that was observed for the first time in the previous 5 days of alerts history. Analysts can use this high-order detection to prioritize triage and response.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/01/14"
  3maturity = "production"
  4updated_date = "2026/09/18"
  5
  6[rule]
  7author = ["Elastic"]
  8description = """
  9This rule detects multiple lateral movement alerts from a user that was observed for the first time in the previous 5 days
 10of alerts history. Analysts can use this high-order detection to prioritize triage and response.
 11"""
 12from = "now-7200m"
 13interval = "9m"
 14language = "esql"
 15license = "Elastic License v2"
 16name = "Lateral Movement Alerts from a Newly Observed User"
 17risk_score = 73
 18rule_id = "e819b7eb-c2d4-4adc-b0c9-658aeb140450"
 19severity = "high"
 20tags = [
 21    "OS: Windows",
 22    "Use Case: Threat Detection",
 23    "Rule Type: Higher-Order Rule",
 24    "Tactic: Lateral Movement",
 25    "Resources: Investigation Guide",
 26    "Noise: Low",
 27    "Performance: Normal",
 28    "Rule Type: ES|QL",
 29    "Platform: Windows",
 30    "Domain: Endpoint",
 31]
 32timestamp_override = "event.ingested"
 33type = "esql"
 34
 35query = '''
 36FROM .alerts-security.* METADATA _index
 37
 38// Lateral Movement related rules
 39| where kibana.alert.rule.threat.tactic.name is not null and user.id is not null and 
 40        (to_string(user.id) like "S-1-5-21*" or to_string(user.id) like "S-1-12-*") and
 41        host.id is not null and KQL("""kibana.alert.rule.threat.tactic.name : "Lateral Movement" """) and
 42        not KQL("""kibana.alert.rule.tags : "Rule Type: Higher-Order Rule" """)
 43
 44// aggregate stats by user.id
 45| stats  Esql.first_time_seen = MIN(@timestamp),
 46         Esql.alerts_count = count(*),
 47         Esql.unique_rules_count = COUNT_DISTINCT(kibana.alert.rule.name),
 48         Esql.unique_count_host_id = COUNT_DISTINCT(host.id),
 49         Esql.rule_name_values = VALUES(kibana.alert.rule.name),
 50         Esql.host_id_values = VALUES(host.id),
 51         Esql.host_ip_values = VALUES(host.ip),
 52         Esql.source_ip_values = VALUES(source.ip),
 53         Esql.process_cmd_line = VALUES(process.command_line),
 54         Esql.tactic_name_values = VALUES(kibana.alert.rule.threat.tactic.name) by user.id, user.name
 55
 56// at least 2 unique lateral movement detection rules from same user.id and that was first seen in last 5 days
 57| eval Esql.date_diff = DATE_DIFF("minute", Esql.first_time_seen, now())
 58| where Esql.unique_rules_count >= 2 and
 59        // matches are within 10m of the rule execution time to avoid alert duplicates
 60        Esql.date_diff <= 10
 61| eval source.ip = MV_FIRST(Esql.source_ip_values),  host.id = MV_FIRST(Esql.host_id_values) 
 62| KEEP Esql.*, user.id, user.name, host.id, source.ip
 63'''
 64note = """## Triage and analysis
 65
 66### Investigating Lateral Movement Alerts from a Newly Observed User
 67
 68This rule surfaces newly observed, low-frequency source user triggering multiple lateral movement alerts.
 69
 70Because the alert has not been seen previously for this rule and host, it should be prioritized for validation to determine
 71whether it represents a true compromise or rare benign activity.
 72
 73### Investigation Steps
 74
 75- Identify the source user, affected hosts and review the associated rule name to understand the behavior that triggered the alert.
 76- Validate the source address and user context under which the activity occurred and assess whether it aligns with normal behavior for that address.
 77- Refer to the specific rule investigation guide for further actions.
 78
 79### False Positive Considerations
 80
 81- Administrative scripts or automation tools can trigger behavior-based detections when first introduced.
 82- Security tooling, IT management agents, or EDR integrations may generate new behavior alerts during updates or configuration changes.
 83- Development or testing environments may produce one-off behaviors that resemble malicious techniques.
 84
 85### Response and Remediation
 86
 87- If the activity is confirmed malicious, isolate the affected host to prevent further execution or lateral movement.
 88- Terminate malicious processes and remove any dropped files or persistence mechanisms.
 89- Collect forensic artifacts to understand initial access and execution flow.
 90- Patch or remediate any vulnerabilities or misconfigurations that enabled the behavior.
 91- If benign, document the finding and consider tuning or exception handling to reduce future noise.
 92- Continue monitoring the host and environment for recurrence of the behavior or related alerts."""
 93references = ["https://www.elastic.co/docs/solutions/security/detect-and-alert/about-detection-rules"]
 94
 95[[rule.threat]]
 96framework = "MITRE ATT&CK"
 97[rule.threat.tactic]
 98id = "TA0008"
 99name = "Lateral Movement"
100reference = "https://attack.mitre.org/tactics/TA0008/"

Triage and analysis

Investigating Lateral Movement Alerts from a Newly Observed User

This rule surfaces newly observed, low-frequency source user triggering multiple lateral movement alerts.

Because the alert has not been seen previously for this rule and host, it should be prioritized for validation to determine whether it represents a true compromise or rare benign activity.

Investigation Steps

  • Identify the source user, affected hosts and review the associated rule name to understand the behavior that triggered the alert.
  • Validate the source address and user context under which the activity occurred and assess whether it aligns with normal behavior for that address.
  • Refer to the specific rule investigation guide for further actions.

False Positive Considerations

  • Administrative scripts or automation tools can trigger behavior-based detections when first introduced.
  • Security tooling, IT management agents, or EDR integrations may generate new behavior alerts during updates or configuration changes.
  • Development or testing environments may produce one-off behaviors that resemble malicious techniques.

Response and Remediation

  • If the activity is confirmed malicious, isolate the affected host to prevent further execution or lateral movement.
  • Terminate malicious processes and remove any dropped files or persistence mechanisms.
  • Collect forensic artifacts to understand initial access and execution flow.
  • Patch or remediate any vulnerabilities or misconfigurations that enabled the behavior.
  • If benign, document the finding and consider tuning or exception handling to reduce future noise.
  • Continue monitoring the host and environment for recurrence of the behavior or related alerts.

References

Related rules

to-top