RDP Lateral Movement Chain Detected
Authentication correlation detected systematic RDP lateral movement: account DA_svc_backup used RDP to connect sequentially to 8 systems over 35 minutes. Pattern started from initial compromised host, moved to file servers, then domain controller. Each hop occurred within 3-5 minutes of arrival on the previous system, consistent with automated lateral movement tooling.


