| CPC H04L 63/14 (2013.01) | 25 Claims |

|
1. A method for detecting lateral movement based on an exposed cryptographic network protocol (CNP) key in a cloud computing environment, comprising:
inspecting a first workload for a private CNP key, the private CNP key associated with a hash of a public CNP key;
detecting a user identifier associated with the private CNP key;
detecting in a security database a representation of the public CNP key;
detecting in the security database a representation of a second workload connected to the representation of a second private CNP key; and
generating a lateral movement path, the lateral movement path including an identifier of the second workload, in response to detecting that the representation of the second private CNP key is connected to the representation of the public CNP key; and
generating a visual graph based on the generated lateral movement path and the detected user identifier.
|