After compromising an initial system, attackers use lateral movement to reach higher-value targets such as sensitive data stores, domain controllers, or privileged accounts. Lateral movement often involves abusing legitimate credentials and tools, such as remote desktop protocols or administrative scripts, which makes it difficult to distinguish from normal activity. Detecting lateral movement requires behavioral analysis and cross-source correlation rather than simple signature matching.