Key Takeaways
- East-west traffic visibility is essential for detecting lateral movement and post-compromise activity inside modern networks.
- Fidelis Network® uses Deep Session Inspection, behavioral analytics, and deception technology to identify anomalies in real time.
- Internal Sensors provide visibility across cloud, hybrid, and on-premises environments without relying only on perimeter defenses.
- Active Threat Detection correlates multiple behavioral signals into high-fidelity MITRE ATT&CK-mapped alerts for faster SOC investigations and response.
Once an attacker gets inside your network, the perimeter stops mattering. They move between internal systems using legitimate protocols, valid credentials, and trusted communication paths. Your boundary tools have no visibility into any of it.
That is the east-west traffic problem. Security teams that lack dedicated east-west traffic monitoring are operating blind to the majority of post-compromise attacker behavior. Detecting east-west traffic anomalies in real time is not an advanced capability anymore. It is a baseline requirement for any organization that takes network security seriously.
Fidelis Network® is built specifically to address this gap. It scans all network traffic bidirectionally, east-west and north-south, to identify threats and signs of data leakage. This article explains how that works in practice, how the detection architecture is structured, and what it means operationally for SOC teams and security architects evaluating NDR solutions.
What Is East-West Traffic and Why Does It Matter for Network Security?
East-west traffic and north-south traffic describe two fundamentally different directions of data flow inside an enterprise environment, and confusing the two leads to serious gaps in security posture.
- North-south traffic crosses the network perimeter. It flows between internal systems and external networks: outbound web requests, incoming email, cloud API calls, remote access through VPN. Traditional security controls sit at these boundary points by design. Intrusion detection systems, intrusion prevention systems, and perimeter firewalls are all built to inspect this direction of traffic flow.
- East-west traffic stays inside the network. It moves laterally between internal systems: workstation to server, server to database server, virtual machine to virtual machine, container to container, on-premises host to cloud workload within the same data center or VPC. East-west traffic occurs constantly in modern enterprise environments. Distributed applications, microservices, Active Directory replication, file sharing, internal APIs, and backup jobs all generate east-west network traffic, none of which crosses a perimeter firewall.
Unlike north-south traffic, east-west communication has no natural chokepoint for inspection. Intra-VLAN traffic, VM-to-VM communication on the same hypervisor, and lateral flows within a cloud environment frequently never reach a device capable of inspecting it.
The operational consequence is direct. An attacker inside your network can perform internal reconnaissance, harvest credentials, access a database server, pivot to a domain controller, and stage valuable data for exfiltration, all across east-west paths, without generating a single alert in a perimeter-focused security stack. Gaining visibility into this layer is what separates organizations that detect breaches early from those that find out weeks later.
What Attackers Do After Initial Access Inside Your Network
Post-compromise behavior follows recognizable patterns mapped across the MITRE ATT&CK Lateral Movement tactic (TA0008). Each stage generates distinctive east-west network traffic that is detectable given the right visibility and anomaly detection systems in place.
Internal reconnaissance comes first. Attackers map the internal network through ICMP sweeps, ARP broadcasts, SMB enumeration, LDAP queries against Active Directory, and NetBIOS/NBNS requests to a DNS server or name resolution service. The resulting traffic pattern is statistically rare: a small number of source hosts reaching an unusually broad range of internal destinations in a compressed window. This is exactly the type of behavioral deviation that anomaly detection systems are designed to surface.
Credential abuse follows reconnaissance. Attackers extract NTLM hashes or Kerberos tickets from memory using tools like Mimikatz, then authenticate laterally via RDP (T1021.001), SMB (T1021.002), WinRM (T1021.006), or SSH (T1021.004). Pass-the-hash (T1550.002) uses valid credentials tied to a legitimate user account, which is why it bypasses authentication-log-only detection. The credentials are real. Only the connection pattern and internal traffic behavior reveals the anomaly.
Internal C2 relay is increasingly common in sophisticated attacks. Attackers route command-and-control through compromised internal systems or use DNS tunneling directed at an internal DNS server. The C2 channel exits only after internal relay, making it appear as routine internal communication to north-south monitoring tools that never see the lateral data flow.
Data staging precedes exfiltration. Attackers consolidate internal data from file servers, SharePoint, and database servers onto a single staging host before pushing it outward. This generates abnormal traffic volume in internal file transfers, large sustained SMB or HTTPS sessions that deviate significantly from the normal behavior baseline of those hosts.
All of this happens across protocols that internal systems use legitimately every day. Detecting these potential threats requires east-west traffic visibility and behavioral analytics capable of separating normal behavior from attacker movement across compromised systems.
Why Traditional Security Tools Cannot Monitor East-West Traffic
The reason traditional perimeter-focused security controls miss east-west threats is structural. If the traffic never crosses the inspection point, the tool never sees it. This is not a product limitation. It is a geometry problem.
Firewalls and intrusion prevention systems only inspect traffic that traverses them. Intra-VLAN communication, VM-to-VM traffic within the same hypervisor, and flows within a cloud VPC do not cross the firewall. Intrusion detection systems deployed at network ingress and egress face the same constraint. East-west traffic that stays within a subnet or segment never reaches those sensors.
NetFlow-based tools confirm that two internal systems communicated and how much data moved, but provide no application-layer context. They cannot tell you what was transferred, whether a legitimate protocol was being abused for lateral movement, or whether the data flow contained malicious content. Flow data without session depth is connection metadata, not threat intelligence. Fidelis Network® addresses this limitation by collecting more than 300 metadata attributes from protocols and files, giving analysts substantially richer context than flow records alone.
Endpoint detection captures process execution, file activity, and local network connections on individual managed hosts, but requires an agent on every relevant system. It provides limited network-layer context for east-west lateral movement occurring between internal systems, particularly when attackers use legitimate administrative protocols like WinRM or RDP that generate no endpoint-level malware signal.
As the Fidelis NDR Buyer’s Guide frames it, NDR “continuously scans network traffic and traffic metadata within internal networks (east-west) and internal and external networks (north-south),” complementing rather than duplicating endpoint and perimeter controls.
In cloud infrastructure and hybrid environments, the coverage gap grows wider. East-west communication between cloud-hosted workloads, within a VPC or across distributed systems in the same data center environment, sits entirely outside on-premises sensor visibility without deliberate instrumentation. Many organizations discover this gap only after a security incident.
How Fidelis Network® Is Built for East-West Traffic Monitoring
Fidelis Network® addresses east-west traffic visibility through deliberate sensor placement and a purpose-built inspection engine designed for internal network coverage. The platform uses two distinct sensor types, each optimized for its traffic context.
Direct Sensors handle north-south traffic at ingress and egress points, managing high volumes of short sessions typical of web, email, and external API traffic. They operate inline or out-of-band.
Internal Sensors are positioned specifically for east-west traffic monitoring, placed to capture lateral communication across internal network segments, including high-value assets such as enterprise file shares, SharePoint servers, and database servers. They provide bidirectional threat visibility while supporting advanced threat detection, command-and-control disruption, data exfiltration prevention, lateral movement detection, suspicious host identification, malware detection, and behavioral anomaly detection. Both sensor types operate on mirrored copies of network traffic, inline or out-of-band, without introducing latency into production flows.
The CommandPost provides centralized policy management and alert correlation. The Fidelis Collector stores rich session metadata for retrospective analysis, enabling detection of past attacks and investigation of what occurred before and after any alert fires. The Fidelis Insight feed continuously updates threat intelligence, rules, and policies, automatically applying new indicators to stored retrospective metadata so that newly published IoCs are checked against historical traffic without reprocessing raw packets.
For cloud and hybrid deployments, the Fidelis Network® Cloud architecture keeps sensors deployed within the customer environment, where they analyze traffic locally. These sensors communicate with cloud-hosted CommandPost and Collector components over a secure TLS 1.2 encrypted tunnel. Each deployment operates within a dedicated, isolated virtual network, ensuring customer data separation and security.
In virtualized environments, VMware-based sensors extend visibility into east-west traffic between workloads without requiring additional physical hardware, enabling consistent monitoring across on-premises and cloud infrastructure.
How Deep Session Inspection Works to Detect East-West Threats
The foundational inspection technology in Fidelis Network® is patented Deep Session Inspection (DSI) engine. Rather than inspecting packets individually, DSI reconstructs complete sessions, decodes protocols and applications, analyzes nested and compressed content, and performs real-time threat and data inspection across the entire communication stream.
Standard deep packet inspection tools evaluate individual data packets in isolation. Each packet is matched against rules as it arrives, with no memory of the session context. This approach cannot reconstruct multi-packet application exchanges, decode content embedded inside compressed archives, or analyze application-layer behavior across a complete session.
DSI operates differently. As data packets arrive, the DSI engine assembles them into a session buffer, reconstructs the full application-layer exchange, decodes the protocol and application, and extracts embedded content including nested and compressed files. This happens at wire speed across all ports and protocols, with a single 1U sensor sustaining throughput at up to 20 Gbps.
For east-west traffic specifically, this means Fidelis can analyze what is actually moving between internal systems, not just that a connection occurred. An SMB session carrying a malicious executable, a WinRM command spanning multiple packets, RDP authentication from a user account that has never accessed that host, or a file transfer that decompresses to reveal embedded malicious content, all become inspectable at the application layer.
More than 300 metadata attributes from protocols and files are extracted per session and stored by the Collector independent of whether the session triggered a real-time alert. When new indicators arrive through Fidelis Insight, they are automatically applied to that stored metadata, enabling retroactive detection without reprocessing raw traffic. Full packet capture (PCAP) and real-time layer 7 analysis with content decoded by protocol or application are also supported.
- Content Inspection
- Content Identification
- Full Session Reassembly
- Protocol and Application Decoding
How Fidelis Detects East-West Traffic Anomalies Using Behavioral Analytics
Signature-based detection catches known threats. Behavioral analytics is what catches east-west threats that use legitimate protocols, valid credentials, and normal-looking traffic patterns. Fidelis NDR evaluates network activity across five behavioral contexts, each targeting a distinct class of attacker behavior that generates anomalies detectable through machine learning and statistical modeling.
External context applies machine learning algorithms to north-south traffic to flag statistically rare patterns: services contacted by only a small number of internal hosts, C2 beaconing to newly registered domains, communication on uncommon ports, and anomalous DMZ volume that may indicate active targeting.
Internal context is where east-west traffic anomalies surface. Fidelis evaluates connection pair patterns (who is communicating with whom), protocol behavior between those pairs, and traffic volume relative to baseline. A workstation opening SMB connections to a domain controller for the first time is a connection-pair anomaly. A user account authenticating via RDP to multiple new internal hosts in a short window is a privilege-pivot pattern. These deviate measurably from normal behavior and are consistent with lateral movement across internal systems.
Application protocol context models expected protocol behavior across the internal network. DNS query volume, record types, and domain name entropy deviate measurably when DNS is being used for tunneling toward an internal DNS server or when domain generation algorithms are active. Fidelis uses both unsupervised machine learning and supervised classifiers to detect DGA domains and protocol abuse. A rare TLS fingerprint combined with a newly registered external destination, two anomalies from separate contexts on the same internal host, produce a high-confidence C2 detection.
Data movement context flags volume deviations in internal data flows. Large transfers from a database server to systems that have never previously accessed it, or bulk transfers to a staging host inconsistent with normal operational traffic patterns, surface as indicators of pre-exfiltration data staging.
Event correlation across all four contexts is what the Fidelis Active Threat Detection. Instead of treating individual alerts as isolated events, the platform automatically correlates related behavioral signals, maps them to the MITRE ATT&CK framework, and generates high-fidelity detections with the context needed for faster investigations. When two or more anomalies from different behavioral contexts affect the same internal assets within a short time, they are combined into a single, higher-confidence alert with significantly richer investigative context than any single signal could provide. This approach enables Fidelis to detect east-west traffic anomalies in real time while reducing false positives by evaluating multiple behavioral indicators together rather than relying on isolated deviations.
What East-West Threat Detection Looks Like in a Real Attack
A finance department workstation is compromised through credential theft. The attacker establishes a C2 channel over HTTPS to a domain registered 48 hours earlier. The TLS certificate is valid. To a north-south tool, the traffic resembles normal web browsing.
Fidelis Network®‘s external behavioral context evaluates the TLS session metadata. The JA3 fingerprint matches a known malware framework in Fidelis Insight threat intelligence. The destination domain has no prior communication history from any internal host. A high-fidelity C2 alert fires before any lateral movement begins.
The attacker extracts NTLM hashes from LSASS and uses them to authenticate via SMB to three peer workstations on the same subnet, a pass-the-hash technique (T1550.002). Fidelis Network®‘s internal behavioral context detects the connection pair anomaly: the finance workstation has never previously initiated SMB connections to peer workstations and has now opened three new connections within minutes. Active Threat Detection correlates this with the earlier C2 alert on the same host and produces a compound lateral movement detection mapped to the relevant MITRE ATT&CK technique.
The attacker accesses a file server and begins pulling documents. Fidelis Network®‘s data movement context detects the volume deviation: the file server is transferring substantially more data to this workstation than its behavioral baseline reflects.
At each stage, detections are MITRE-mapped, grouped into a single correlated alert, and surfaced in the CommandPost with session metadata available for immediate drill-down. The SOC has the full attack timeline, affected hosts, internal traffic paths, and session-level evidence before the attacker reaches their primary objective. This is what detecting east-west traffic anomalies in real time looks like operationally.
Can Fidelis Detect Threats in Encrypted East-West Traffic?
Yes. Encrypted east-west traffic is a significant and growing challenge. TLS is broadly deployed across internal services, and some attackers deliberately route lateral activity through encrypted channels to evade content-based inspection. Decrypting everything inline creates privacy exposure, compliance risk, certificate management overhead, and performance impact.
Fidelis Network® profiles encrypted TLS traffic by distinguishing human-driven activity from machine-generated communications using behavioral models and encrypted session metadata.
DSI reconstructs TLS/SSL sessions from mirrored traffic and extracts metadata including JA3 and JA3S fingerprints, certificate chain details, cipher suite selections, handshake timing metrics, and packet-size distributions, without decrypting payload content. Machine learning models profile normal encrypted traffic patterns for each internal host and flag deviations consistent with C2 tunneling, self-signed certificates on unexpected internal connections, or packet-size distributions consistent with command beaconing behavior.
For DNS specifically, Fidelis Security’s published documentation on DNS tunneling confirms the platform monitors east-west traffic to detect covert data communication via DNS and flags repetitive requests from internal hosts to untrusted domains as indicators of C2 or staged data exfiltration attempts.
How Fidelis Deception Catches Lateral Movement That Bypasses Behavioral Analytics
Behavioral analytics requires threshold calibration. Tighten thresholds and you catch more activity but generate more alerts requiring triage. Loosen them and you reduce noise but create detection gaps. Fidelis Deception® adds a complementary layer that sidesteps this challenge entirely.
Integrated Deception extends detection by automatically deploying decoys and breadcrumbs throughout the environment, generating high-fidelity alerts whenever an attacker interacts with assets that should never be accessed during normal operations.
Fidelis Deception® places assets throughout the internal network: fake servers, planted credentials, ghost Active Directory accounts, and breadcrumb files positioned across endpoints and file shares. No legitimate user or process ever touches these assets under normal operations. Any interaction with a decoy is definitionally anomalous and generates an immediate high-fidelity alert.
When an attacker performing internal reconnaissance follows a breadcrumb to a ghost server, queries a fake AD account, or attempts to authenticate using a planted credential, the alert fires with full session context. There is no threshold to calibrate and no baseline to establish. The detection is binary: either someone touched a decoy or they did not.
Within the Fidelis Elevate® XDR platform, Fidelis Deception® integrates with Fidelis Network® to combine deception activity with east-west network telemetry for richer investigation context and broader visibility across the IT environment. When an attacker interacts with a decoy on a specific internal host, that activity is automatically correlated with behavioral anomalies detected by Fidelis Network® on the same system. The result is a high-confidence detection that provides documented attacker TTPs, movement paths, and valuable context before the attacker reaches a legitimate network resource.
Can Fidelis Monitor East-West Traffic in Cloud and Hybrid Environments?
Fidelis uses the same sensor architecture for both on-premises and cloud deployments, allowing cloud-based sensors to perform the same east-west monitoring role as Internal Sensors deployed inside traditional enterprise networks.
The Fidelis Network® supports flexible deployment across on-premises hardware, VMware virtual machines, and cloud environments, allowing organizations to operate the solution within their own infrastructure while using cloud-hosted components for centralized management and analytics. In cloud deployments, sensors remain within the customer environment and communicate securely with cloud-hosted CommandPost and Collector components over encrypted TLS 1.2 connections. Each deployment operates within a dedicated, firewalled virtual network to maintain customer isolation, while metadata can be retained either on-premises or in the cloud based on operational and compliance requirements.
For security architects designing coverage across distributed systems and hybrid cloud infrastructure, the same detection framework, DSI, behavioral analytics across five contexts, Active Threat Detection, and MITRE ATT&CK mapping, applies in cloud-deployed configurations as it does on-premises. East-west communication within cloud environments, between virtual machines, between workloads in the same data center or VPC, falls within the coverage scope of appropriately positioned Fidelis sensors.
Subscription pricing for the cloud model is based on aggregate peak monitored bandwidth and days of metadata retention, scaling with network traffic volume as infrastructure grows.
How SOC Teams Use Fidelis to Investigate East-West Security Incidents Faster
Alert triage benefits directly from Active Threat Detection. Rather than triaging isolated, low-context events across multiple consoles, analysts receive a single correlated alert covering the full attack sequence with pre-stage evidence already assembled. Active Threat Detection automatically validates, correlates, and consolidates network alerts into a single view, providing analysts with pre-stage evidence before investigations begin. This is how security teams move from alert to triage decision in minutes rather than hours during active security incidents.
Investigation uses DSI session metadata stored by the Collector. Analysts examine protocol behavior, file content, connection pair history, and timing for any flagged session without rebuilding events from scattered log sources. Full PCAP is accessible for forensic reconstruction. The depth of data available means incident response begins with context, not correlation work.
Threat hunting leverages Collector metadata to search weeks of historical traffic for behavioral patterns. Hunters query across multi-host relationships and temporal sequences: hosts initiating SMB connections to a domain controller within a defined window following an unexpected inbound connection from a workstation subnet, filtered for pairs with no prior connection history. MITRE ATT&CK mapping provides a shared framework for expressing hunt hypotheses and documenting findings.
Retrospective detection runs automatically when new intelligence arrives. Fidelis Insight applies new indicators to stored metadata, surfacing attacker activity that predates the indicator’s publication without requiring analysts to re-run manual queries.
Automated response through CommandPost playbooks integrates with EDR solutions and SOAR platforms to terminate suspicious connections, quarantine affected endpoints, block malicious IPs and URLs, and drop traffic flows, compressing the time between detection and containment.
- Comprehensive Threat Detection & Analysis
- Data Loss Prevention (DLP) & Email Security
- Deep Session Inspection & TLS Profiling
Why East-West Traffic Visibility Is Now a Baseline Security Requirement
Many organizations still treat east-west traffic monitoring as a secondary or advanced capability, something to layer in after perimeter controls are mature. The evidence from incident response investigations consistently tells a different story: attackers who achieve initial access inside a network operate across internal systems for extended periods precisely because east-west visibility is absent.
Perimeter defenses remain essential. But hybrid cloud infrastructure, remote access through VPN, third-party connectivity, and credential-based initial access mean that some threats will reach the internal network. When that happens, comprehensive network security requires comprehensive visibility, and that means east-west traffic security with the same depth of inspection applied to lateral internal flows as to boundary-crossing north-south traffic.
Fidelis Network® provides the internal network observability required: patented Deep Session Inspection® at wire speed, Internal Sensors specifically positioned for east-west coverage, more than 300 metadata attributes extracted from protocols and files per session, behavioral analytics across five contexts producing MITRE-mapped Active Threat Detection alerts, integrated deception generating high-fidelity detections during internal reconnaissance, and flexible deployment across on-premises hardware, VMware, and cloud environments.
As part of the Fidelis Elevate® XDR platform alongside Fidelis Endpoint® and Fidelis Deception®, network detections correlate with endpoint data and deception layer telemetry for unified visibility across network, endpoint, and deception layers.
For NDR evaluators, the questions that matter are concrete: where are sensors positioned relative to actual east-west traffic flows, what session-level inspection depth do they provide, and does the behavioral detection framework surface anomalies across internal communication rather than only at the perimeter?
Fidelis Network® addresses all three directly, with architecture documentation to verify each claim.
Frequently Asked Questions
What does detecting east-west traffic anomalies in real time actually mean?
It means continuously monitoring lateral communication between internal systems, comparing observed traffic patterns, connection pairs, protocol behavior, and data volumes against established behavioral baselines, and surfacing statistically anomalous deviations as they occur rather than after the fact. Fidelis Network® does this using Deep Session Inspection and machine learning-based behavioral analytics applied to east-west network traffic across all ports and protocols, with alert correlation mapping findings to MITRE ATT&CK in real time.
What is east-west traffic in network security?
East-west traffic refers to lateral data communication between systems inside the same network: server to server, workstation to workstation, VM to VM, container to container. Unlike north-south traffic, which crosses the network perimeter to and from external systems, east-west traffic stays inside the internal network. In modern data centers and cloud environments, east-west communication represents the majority of total network traffic volume and is where most post-compromise attacker lateral movement occurs.
Why is east-west traffic security harder to implement than perimeter security?
North-south traffic crosses defined boundary points where security controls are naturally positioned. East-west traffic flows between internal systems and may never cross a perimeter device. Comprehensive east-west traffic security requires sensors positioned inside the network at core switching infrastructure or on virtual and cloud infrastructure, combined with session-level inspection depth sufficient to detect anomalies in traffic patterns that use legitimate protocols and valid credentials.
How does Fidelis Network® detect lateral movement in east-west traffic?
Fidelis Network® positions Internal Sensors to capture east-west communication and analyzes it using Deep Session Inspection and behavioral analytics across five contexts. The internal behavioral context evaluates connection pair patterns and flags statistically rare peer-to-peer communication, protocol deviations between internal hosts, and data volume anomalies. Active Threat Detection correlates signals across contexts and maps findings to MITRE ATT&CK. The attack scenario section of this article describes how this works across a real credential-abuse-to-lateral-movement attack chain.
What does Deep Session Inspection do that standard DPI cannot?
Standard DPI evaluates individual packets against predefined rules in isolation. Deep Session Inspection reassembles the full application-layer session, enabling inspection of multi-packet exchanges, decoding of nested and compressed content, protocol and application identification, and real-time content and DLP analysis. DSI also stores more than 300 metadata attributes from protocols and files per session for retrospective analysis, enabling threat hunting and retroactive detection against newly published indicators.
Can Fidelis Network® analyze encrypted internal traffic?
Yes. Fidelis Network® profiles encrypted east-west traffic using metadata attributes extracted during session reconstruction: JA3 and JA3S fingerprints, certificate chain details, cipher suite selections, handshake timing metrics, and packet-size distributions. Machine learning models profile normal encrypted behavior per internal host and flag deviations consistent with C2 tunneling, rogue certificates, or beaconing, without decrypting payload content.
What is Fidelis Active Threat Detection?
Active Threat Detection is Fidelis Network®‘s alert correlation engine, confirmed in the Fidelis Network® Datasheet as providing “automatic correlation of alerts, threat mapping against the MITRE ATT&CK framework, high-fidelity alerts.” It automatically correlates anomalies from multiple behavioral contexts affecting the same internal hosts, producing compound high-fidelity alerts that give SOC analysts the full attack chain context in a single view rather than isolated individual detections.
Does Fidelis Network® support cloud and hybrid environments?
Yes. The Fidelis Network® Cloud model places sensors on customer premises communicating over a TLS 1.2 encrypted secure tunnel to cloud-hosted CommandPost and Collector components. VMware virtual sensor deployment is also supported. The Fidelis Network® Datasheet confirms flexible deployment across on-premises hardware, virtual machines, and cloud environments, with each customer instance running in a dedicated, separately firewalled virtual network.
Citations:
- ^https://attack.mitre.org/tactics/TA0008/
- ^https://attack.mitre.org/techniques/T1021/
- ^https://attack.mitre.org/techniques/T1550/
- ^https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure
- ^https://www.cisa.gov/news-events/cybersecurity-advisories