read
A link to a blog post I worked on for Palantir with help from friends at SpecterOps regarding SMB based lateral movement
Quick summary:
- Maps common SMB-driven lateral movement paths seen during adversary simulation.
- Prioritizes segmentation and host controls that meaningfully constrain attacker mobility.
- Emphasizes phased rollout patterns so restrictions can be adopted without breaking operations.