
In the second of three articles, Adrian Bishop at Huntsman Security explains how an attacker might explore a compromised network, and how they can discover and compromise other systems and accounts
In my last article, we analysed the first three stages of an assault, showing how an attacker could compromise a system and establish a persistent presence.
In this piece, let’s pick up from stage four and discuss how an attacker might explore a compromised network, and how they can discover and compromise other systems and accounts. This is the precursor to a data breach, and a critical moment for both the attacker and the organisation being targeted. A lot can be lost and gained depending on what you can spot in this moment!
So far in our scenario, the target user has downloaded malicious content from a website that exploited an operating system vulnerability to run code with privileges the user does not normally have. This allows the code to perform actions with operating system or administrator permissions, such as creating scheduled tasks, installing software, or changing system configurations.
How did they achieve this? The Techniques within the Privilege Escalation Tactic contain methods that enable commands or software to be executed with higher privileges than the user holds, including:
Our attack scenario uses a single Technique to gain higher privileges:
The Privilege Escalation exploit allows the malicious script to use Microsoft’s Background Intelligent Transfer Service (BITS) administration features to create BITS Jobs to download and launch additional software.
For an attacker to succeed in infiltrating a network they must remain undetected. Any actions they perform must be either undetectable or appear to be normal activity for the host they are performed on.
Some Defence Evasion Techniques our attacker might employ include:
In our scenario, to avoid detection the attacker uses:
Included within this downloaded software is an automated tool suite which can further compromise the system. The suite of tools is executed with elevated privileges and used to search for valid user accounts that may provide additional access to systems. The tools include ways to search for cached Windows credentials on the local host, as well as credentials in files and browser caches. In addition, it installs a keylogger, to capture credentials used by the user for remote system access.
Once an attacker can upload and execute software on a host, they begin to search for information that will help them infiltrate further into the system or network. The most valuable data they will seek is valid account credentials. These credentials make their actions easier to perform and harder to detect, especially if they manage to find details for a user with higher privileged access to some or all systems. This activity is within the Credential Access Tactic and includes:
At this stage, our attacker uses the following Techniques:
After exploring the compromised system for credentials, the attacker uses built-in and custom utilities to gather information about the host network, the Windows domain it belongs to, and sensitive groups and users within the domain.
Once an attacker has gathered credential data from the local system, they then discover other useful information about the system, the attached network, and remote systems. After searching the compromised host for useful information, data and credentials, an attacker will map out the surrounding network. This may be done over a period of time to avoid detection and ensure they discover as much information as possible.
The primary objective of this stage is to determine the next targets for attack and the methods to use.
The Discovery Tactic includes Techniques for discovering information, including:
Within the discovery stage of our attack scenario the attacker used a combination of Techniques:
After discovering other targets of interest, the attacker uses the retrieved account credentials to remotely execute commands on the discovered hosts. They also copy any required software and tools to network file shares from where it can be downloaded to systems they are targeting.
From the discovery stage the attacker can build a list of target systems and applications they want to compromise next. Depending upon the account credentials the attacker has harvested in the previous stage this may be a trivial task, and their ability to move around the network may be quick. Alternatively, they may have to wait for additional information or user credentials to be discovered before this can occur.
The Lateral Movement Tactic includes Techniques covering:
For this attack stage the movement of software and control to different systems utilises:
The good news is that there are steps organisations can take to help mitigate the techniques described above. MITRE ATT&CK specifically identifies several mitigation strategies. These include:
There are also monitoring and detection activities that SOC teams can perform that point towards a potential attack:
Following the steps outlined above should mean you are able to thwart the attack before it reaches the data breach stage. For those that can’t achieve this, the next article will highlight what happens when attackers gather and exfiltrate sensitive data, whilst preventing the recovery of it, so be sure to check-back for the final part in a couple of weeks!
Adrian Bishop is Head of Engineering at Huntsman Security
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543