The technology addon 'TA-latmov' was designed based off SANS' 2018 Hunt Evil Poster. This poster focuses on lateral movement from forensic evidence found on the source/destination endpoint after the action has occurred.
Based on this, I created a series of Windows-based inputs to capture the state for threat hunting and preservation.