A methodological approach to investigating lateral movement attacks using a threat hunting architecture
Loading...
Date
Authors
Researcher ID
Supervisors
Journal Title
Journal ISSN
Volume Title
Publisher
North-West University (South Africa)
Record Identifier
Abstract
In this study, the application of hypothesis-driven threat hunting methodologies to detect lateral movement attacks is investigated. Lateral movement attacks, as pivotal components of advanced persistent threats (APTs), enable attackers to stealthily navigate and exploit compromised networks by moving from one compromised system to another within the same network. One approach to detecting such threats is through threat hunting, which involves proactively identifying threats based on known tactics and behaviours. A key focus of this study is the Targeted Hunting integrated Threat Intelligence (TaHiTI) methodology. The primary objective is to investigate the applicability of TaHiTI and assess its potential for improving cybersecurity defences against lateral movement attacks. This is achieved using a simulation-based experimental design that replicates various attack scenarios within a controlled virtual laboratory. Through a structured qualitative approach supported by experimental simulation, this study assesses the applicability of the TaHiTI methodology in detecting lateral movement attacks. The findings highlight the strengths of the methodology in detecting stealthy attacker behaviours and its relevance for practical implementation in cybersecurity operations. Limitations related to simulation-based research are discussed, along with opportunities for future work, including real-world testing and expanded threat modelling. The study contributes to both academic and applied cybersecurity by demonstrating how structured, intelligence-driven hunting strategies can advance the detection of sophisticated intrusions.
Sustainable Development Goals
Description
Master of Science in Computer Science, North-West University, Potchefstroom Campus
