What separates horizontal from vertical privilege movement, and what does neither measure?
answer
- route taken, not damage done
- boundary crossed versus credential presented
- a peer can hold far more than you
- ladders are a single-host idea
- ATT&CK files account use under four tactics
basics
~20 sVertical movement acquires rights an identity lacks; horizontal movement takes over a peer identity holding different rights. Both describe the route, not the damage. A sideways step onto an identity that already owns production ends the intrusion.
solid answer
~50 sVertical movement means the identity you control gains rights it did not have, crossing a boundary the system was built to enforce. Horizontal movement means you stop using that identity and start using another one of comparable standing, by presenting its credential. The distinction describes the mechanism of the step, and it gets routinely mistaken for a measure of seriousness. It is not. What matters is what the identity you end up holding can reach. If a peer service account already holds production database rights, moving sideways onto it is the whole objective, with no boundary crossed anywhere. In practice the two collapse: an operator does not care whether the next credential belongs to something nominally above them, only whether it carries the entitlement they want. Treat `no privilege escalation occurred` as a statement about technique, never as a statement about impact.
go deeper
Be ready to define both terms in one sentence each and to say plainly that they describe the route, not the harm. Knowing that a sideways step can be the end of the story is what the screener is checking.
An interviewer expects you to explain why the ladder is a single-host idea and why a directory has no rungs, then show the mechanism is identical in both cases: get a credential, present it.
Demonstrate that you grade by reach, repeatability and durability rather than by which word applies. Bring a concrete inversion — a high-privilege step that reached nothing next to a peer step that reached production.
Own the consequence for how work is prioritised: if the vocabulary drives severity, an estate systematically under-rates the routes that need no defect at all and over-rates the ones a host fix closes.
## The two words **Vertical privilege movement** (usually called privilege escalation) means the identity currently under an operator's control ends up with rights it did not have. Something the system actively enforces gets crossed: an unprivileged Windows token becomes an administrative one, a non-root Linux process becomes uid 0, an application account that could read becomes one that can write. **Horizontal privilege movement** means control passes to a *different* identity of comparable standing. Nothing is elevated. The operator simply stops authenticating as A and starts authenticating as B, because they now hold something B can authenticate with. That is the whole distinction, and it is a distinction about **how the step was taken**, not about how much the step reached. ## Where the distinction is genuinely real On a single machine. An operating system kernel maintains an enforced gap between an unprivileged context and a privileged one, and that gap is a designed boundary with a designed guard. The same is true inside a single application that checks a role before an action. In those places "up" is well defined, because someone drew the ladder and wrote code to police it. ## Where it stops being real In a directory, or in a workload-identity estate, authorisation attaches to each identity as a *set of entitlements*, and those sets are not ordered. There is no rung above another rung. "Administrator" is not a level; it is an identity with an unusually generous set attached. Two peer accounts may hold wildly different power with no enforced boundary between them, because there is no boundary to enforce, only two separate credentials. So in that environment the two movements are the same operation: obtain a credential and present it. The result differs only in what the new identity happens to hold. ## What an operator is actually optimising Not rank. **Reach, per unit of cost.** The question an operator asks about the next identity is "does it already hold the entitlement I need, and how cheaply can I get something that authenticates as it?" A top-tier administrative credential is expensive to obtain and heavily watched; a build identity or a workload identity is often neither, and frequently holds more of what the objective requires. Choosing the cheap peer over the expensive superior is ordinary economics, not a compromise on ambition. ## Why the severity error is so common Because the vocabulary came from single-machine security, where the ladder was real and climbing it *was* the achievement. Carried into an estate, it produces two symmetrical mistakes: | Route | Reach | Reality | |---|---|---| | Vertical: root on an isolated bastion holding no data | Almost nothing | Impressive step, trivial consequence | | Horizontal: a peer build identity that can push to production | Everything | Unremarkable step, total consequence | The first is graded high because a boundary broke. The second is graded low because none did. Both gradings are wrong, and they are wrong in the same way: the route was scored instead of the reach. ## The framework declines to help you here MITRE ATT&CK files the use of a legitimate account as **T1078, Valid Accounts**, and lists that single technique under **four** tactics — Initial Access, Persistence, Privilege Escalation and Defense Evasion. The framework explicitly refuses to treat "they just used an account" as a lesser category of act; the same behaviour serves as the escalation *and* as the way the operator stays quiet. If your mental model says account use is a downgrade from escalation, the taxonomy everyone else uses already disagrees with you. ## The one thing the distinction still predicts It predicts what the step *depends on*. A vertical step depends on a defect or a misconfigured primitive that lives on a host, so it exists in one place and can be closed there. A horizontal step depends on two things that live somewhere else entirely: a reusable secret, and an entitlement somebody granted deliberately. That is a useful thing to know about the step. It is still not a severity claim. ## Answering this in a loop Give both definitions in one sentence each, then immediately volunteer the limit: the pair classifies the mechanism, and the interviewer's next question is almost always a scenario where the horizontal step is the catastrophic one. Say what severity actually follows from — what the final identity can act on, how cheaply the same route repeats, and how long it stays available — and you have answered the question they were really asking.
- Give me a case where a purely horizontal step is worse than a vertical one.Root on a hardened bastion that stores nothing and reaches nothing is a vertical step with near-zero consequence. Taking over a peer build identity that is entitled to push images into production is horizontal, crosses no boundary at all, and hands the operator the objective. The route inverted the severity ordering completely.
- Does MITRE ATT&CK treat 'they used a valid account' as something less than escalation?No. T1078 Valid Accounts is listed under Initial Access, Persistence, Privilege Escalation and Defense Evasion — the same technique serves all four purposes. The taxonomy deliberately does not carve out account use as a lesser act, which is exactly the point candidates miss when they downgrade a finding for lacking an escalation step.
- If neither word measures impact, what should you state instead?State reach: name what the identity you ended on can read, write or trigger. Then state repeatability — whether the route needs an exploit or just custody of a credential — and durability, meaning how long the route stays open if nobody changes the entitlement. Those three describe consequence; horizontal and vertical describe only mechanism.
A burglar who picks the lock and one who finds the side door unlocked are standing in the same room. The story of how the door opened is not a measurement of what is in the room.
saying these in an interview costs you the question
- Says horizontal movement is inherently less serious than vertical
- Treats 'nobody became root or domain admin' as 'no real impact'
- Assumes every environment has a privilege ladder to climb
- Calls any gain in rights 'vertical' even between unrelated peer accounts
- Cannot name what the final identity actually reaches