We Watched a Hacker Move Through a Network in Real Time
Geek Heros War Stories
The Alert
At 2:47 PM on a Tuesday, our EDR platform's Security Operations Center called us directly. Not an email. Not a ticket. A phone call. That's how you know it's serious.
"We have an active threat actor in your client's environment. They're moving laterally. We need you to act now."
The SOC analyst walked us through what they were seeing in real time. A threat actor had gained initial access to the network through a single endpoint — a workstation belonging to a staff member whose password was weak enough to be cracked through brute force. From that foothold, the attacker was systematically probing the network, looking for higher-privilege accounts.
They were methodical. Professional. They knew what they were doing.
What We Were Watching
EDR — Endpoint Detection and Response — doesn't just block known malware. It monitors behavior. And the behavior patterns on this network were unmistakable:
- Credential harvesting: The attacker was running tools to extract cached credentials from the compromised workstation. - Lateral movement: They were using those credentials to attempt connections to other machines on the network, looking for one with administrative access. - Privilege escalation: Every move was designed to get closer to domain admin credentials — the keys to the entire kingdom.
The SOC team was watching every step. Every process execution, every network connection, every authentication attempt was logged and analyzed in real time. The attacker didn't know they were being watched.
The Response
We had minutes, not hours. If the attacker reached domain admin credentials, they would have access to everything: email, files, backups, client data. At that point, containment becomes exponentially harder and data exfiltration becomes almost certain.
Here's what we did, in order:
1. Disabled the compromised account. The initial entry point was shut down immediately. The attacker lost their foothold.
2. Isolated the affected endpoint. The compromised workstation was quarantined at the network level — it could no longer communicate with any other device.
3. Rolled all administrative credentials. Every admin account in the environment had its password changed to a 24-character randomly generated string. This wasn't a password change — it was a complete credential reset. If the attacker had harvested any admin credentials, they were now useless.
4. Forced password resets across the organization. Every user account was required to change their password immediately. New complexity requirements were enforced: minimum 16 characters, no dictionary words, no reuse of previous passwords.
5. Enabled enhanced monitoring. The SOC team increased monitoring sensitivity across the entire environment, watching for any sign that the attacker had established a secondary access point.
The Outcome
The attacker was locked out. No data left the environment. No files were encrypted. No client information was compromised. The total time from initial alert to full lockout was under 90 minutes.
Without EDR, this intrusion would have been invisible. Traditional antivirus wouldn't have flagged any of the attacker's actions because they weren't using malware — they were using legitimate tools and stolen credentials. The only reason we caught them was behavioral monitoring that identified the pattern of lateral movement as hostile.
The Aftermath
The immediate crisis was resolved, but the work wasn't done. We conducted a full post-incident review:
- The initial compromise vector was confirmed: a weak password on a single account. - New password policies were enforced organization-wide. - The subsequent weeks saw a spike in password lockout calls as staff adapted to the new complexity requirements. That spike lasted about two weeks before users adjusted. - Long-term, the client's security posture improved dramatically. The incident became a catalyst for security investments the firm had been deferring.
What This Means for Your Firm
> 📋 Read the full case study → [View the Active Intrusion Response case study](#case-studies)
This incident was stopped because of three things: EDR with 24/7 SOC monitoring, fast human response, and prepared credential management procedures. Remove any one of those three, and this story has a very different ending.
Ask yourself: - If an attacker compromised one of your user accounts right now, would anyone know? - How long would it take to detect lateral movement in your network? - Can you roll all admin credentials in under an hour?
If those questions make you uncomfortable, they should. [Take our free site audit](#assessment) and find out whether your firm could survive what this client survived — or whether you'd find out about the intrusion from your clients' data appearing on the dark web.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.