Detecting Credential Theft Lateral Movement: Defender for Cloud and Sentinel KQL
Retrospective: this article looks back at events from June 2017, written in 2026 with the benefit of hindsight.
NotPetya combined credential theft with legitimate admin tools to move across networks. Detecting that pattern early is one of the most effective ways to stop ransomware and destructive attacks before they spread.
Signals worth watching
- Processes accessing LSASS memory (credential dumping).
- Remote service creation or execution via PsExec, WMI or scheduled tasks across many hosts.
- An administrator account signing in to machines it has never used before.
- The same account authenticating to many hosts within minutes.
Where the data lives
- Microsoft Defender for Endpoint: process, logon and network events; built-in alerts for credential theft.
- Microsoft Defender for Identity: sensors on domain controllers detect pass-the-hash, pass-the-ticket and suspicious lateral movement.
- Windows security event logs forwarded to Sentinel (event IDs 4624 logons and 4672 special privileges are the usual starting point).
A starting query
Find accounts logging on to an unusual number of devices in a short period:
DeviceLogonEvents
| where ActionType == "LogonSuccess" and LogonType in ("Network", "RemoteInteractive")
| summarize Devices = dcount(DeviceName) by AccountName, bin(Timestamp, 15m)
| where Devices > 10
Expect noise from management servers and backup tools; exclude their service accounts deliberately and document why.
Response
- Disable or reset the compromised account immediately, including its Kerberos tickets where relevant.
- Isolate the source machine.
- Hunt for persistence on every host the account touched.
- Review why that credential was available on the first machine — the root cause is usually missing tiering.
Speed matters. NotPetya took only minutes to spread across large networks.