Lateral movement detected — attacker stopped before reaching production systems.
A Hamilton County manufacturer engaged SignalPoint after a competitor in their supply chain suffered a ransomware attack. Two months in, our threat hunting team identified active lateral movement — an attacker who had been inside the network for 6 days.
The threat hunt finding
During a scheduled proactive threat hunt aligned to MITRE ATT&CK T1021 (Remote Services), SignalPoint analysts identified anomalous SMB lateral movement between three workstations outside of normal business patterns. The activity had begun 6 days prior — invisible to the client's existing antivirus.
The attacker had entered via a phishing email targeting an accounts payable clerk, establishing persistence through a scheduled task and moving laterally using harvested credentials. Their objective appeared to be the manufacturing execution system (MES) connected to production floor equipment.
Response
All three compromised endpoints were isolated immediately. The attacker's C2 channel was cut. Forensic investigation confirmed the initial access vector, full lateral movement timeline, and complete list of accessed systems. The MES was never reached.
Outcome
Production continued without interruption. Full eradication was completed within 48 hours. The engagement produced an updated network segmentation recommendation that was implemented to isolate the MES from corporate IT going forward.
Want this level of protection for your business? SignalPoint provides the same 24/7 managed EDR and threat hunting to businesses across Chattanooga and the Tennessee Valley — starting at a price point built for SMBs.
Book a free 30-minute consultation