NWU Institutional Repository

A methodological approach to investigating lateral movement attacks using a threat hunting architecture

dc.contributor.advisorSerfontein, Rudien_ZA
dc.contributor.advisorKrüger, Hendrik Abrahamen_ZA
dc.contributor.authorMokoena, Ten_ZA
dc.contributor.researchIDSerfontein, Rudi- 21165750en_ZA
dc.contributor.researchIDKrüger, Hendrik Abraham- 12066621en_ZA
dc.date.accessioned2025-09-11T09:44:40Z
dc.date.issued2025
dc.descriptionMaster of Science in Computer Science, North-West University, Potchefstroom Campus
dc.description.abstractIn this study, the application of hypothesis-driven threat hunting methodologies to detect lateral movement attacks is investigated. Lateral movement attacks, as pivotal components of advanced persistent threats (APTs), enable attackers to stealthily navigate and exploit compromised networks by moving from one compromised system to another within the same network. One approach to detecting such threats is through threat hunting, which involves proactively identifying threats based on known tactics and behaviours. A key focus of this study is the Targeted Hunting integrated Threat Intelligence (TaHiTI) methodology. The primary objective is to investigate the applicability of TaHiTI and assess its potential for improving cybersecurity defences against lateral movement attacks. This is achieved using a simulation-based experimental design that replicates various attack scenarios within a controlled virtual laboratory. Through a structured qualitative approach supported by experimental simulation, this study assesses the applicability of the TaHiTI methodology in detecting lateral movement attacks. The findings highlight the strengths of the methodology in detecting stealthy attacker behaviours and its relevance for practical implementation in cybersecurity operations. Limitations related to simulation-based research are discussed, along with opportunities for future work, including real-world testing and expanded threat modelling. The study contributes to both academic and applied cybersecurity by demonstrating how structured, intelligence-driven hunting strategies can advance the detection of sophisticated intrusions.
dc.description.thesistypeMastersen
dc.identifier.urihttps://orcid.org 0002-3097-5840
dc.identifier.urihttp://hdl.handle.net/10394/43372
dc.language.isoen
dc.publisherNorth-West University (South Africa)
dc.subjectLateral movement detection
dc.subjectAdvanced persistent threats
dc.subjectThreat hunting
dc.subjectTaHiTI methodology
dc.subjectCybersecurity methodologies
dc.subjectMITRE ATT&CK framework
dc.subjectSimulation-based research
dc.subjectProactive threat detection
dc.subjectContinuous innovation
dc.subjectNetwork security
dc.titleA methodological approach to investigating lateral movement attacks using a threat hunting architecture
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Mokoena_T_2025.pdf
Size:
4.53 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: