skip to content

Identity and Credential Attacks

You will learn how one guessed or stolen credential becomes the whole estate, and what each step costs the operator who chose it. Interviewers make you walk that path end to end.

on this pageshow

explore

questions

page 1 of 2

What separates horizontal from vertical privilege movement, and what does neither measure?

level: juniorimportance: must knowfreq 70%

answer

  1. route taken, not damage done
  2. boundary crossed versus credential presented
  3. a peer can hold far more than you
  4. ladders are a single-host idea
  5. ATT&CK files account use under four tactics

basics

~20 s

Vertical movement acquires rights an identity lacks; horizontal movement takes over a peer identity holding different rights. Both describe the route, not the damage. A sideways step onto an identity that already owns production ends the intrusion.

solid answer

~50 s

Vertical movement means the identity you control gains rights it did not have, crossing a boundary the system was built to enforce. Horizontal movement means you stop using that identity and start using another one of comparable standing, by presenting its credential. The distinction describes the mechanism of the step, and it gets routinely mistaken for a measure of seriousness. It is not. What matters is what the identity you end up holding can reach. If a peer service account already holds production database rights, moving sideways onto it is the whole objective, with no boundary crossed anywhere. In practice the two collapse: an operator does not care whether the next credential belongs to something nominally above them, only whether it carries the entitlement they want. Treat `no privilege escalation occurred` as a statement about technique, never as a statement about impact.

go deeper

for a junior

Be ready to define both terms in one sentence each and to say plainly that they describe the route, not the harm. Knowing that a sideways step can be the end of the story is what the screener is checking.

for a middle

An interviewer expects you to explain why the ladder is a single-host idea and why a directory has no rungs, then show the mechanism is identical in both cases: get a credential, present it.

for a senior

Demonstrate that you grade by reach, repeatability and durability rather than by which word applies. Bring a concrete inversion — a high-privilege step that reached nothing next to a peer step that reached production.

for a principal

Own the consequence for how work is prioritised: if the vocabulary drives severity, an estate systematically under-rates the routes that need no defect at all and over-rates the ones a host fix closes.

## The two words **Vertical privilege movement** (usually called privilege escalation) means the identity currently under an operator's control ends up with rights it did not have. Something the system actively enforces gets crossed: an unprivileged Windows token becomes an administrative one, a non-root Linux process becomes uid 0, an application account that could read becomes one that can write. **Horizontal privilege movement** means control passes to a *different* identity of comparable standing. Nothing is elevated. The operator simply stops authenticating as A and starts authenticating as B, because they now hold something B can authenticate with. That is the whole distinction, and it is a distinction about **how the step was taken**, not about how much the step reached. ## Where the distinction is genuinely real On a single machine. An operating system kernel maintains an enforced gap between an unprivileged context and a privileged one, and that gap is a designed boundary with a designed guard. The same is true inside a single application that checks a role before an action. In those places "up" is well defined, because someone drew the ladder and wrote code to police it. ## Where it stops being real In a directory, or in a workload-identity estate, authorisation attaches to each identity as a *set of entitlements*, and those sets are not ordered. There is no rung above another rung. "Administrator" is not a level; it is an identity with an unusually generous set attached. Two peer accounts may hold wildly different power with no enforced boundary between them, because there is no boundary to enforce, only two separate credentials. So in that environment the two movements are the same operation: obtain a credential and present it. The result differs only in what the new identity happens to hold. ## What an operator is actually optimising Not rank. **Reach, per unit of cost.** The question an operator asks about the next identity is "does it already hold the entitlement I need, and how cheaply can I get something that authenticates as it?" A top-tier administrative credential is expensive to obtain and heavily watched; a build identity or a workload identity is often neither, and frequently holds more of what the objective requires. Choosing the cheap peer over the expensive superior is ordinary economics, not a compromise on ambition. ## Why the severity error is so common Because the vocabulary came from single-machine security, where the ladder was real and climbing it *was* the achievement. Carried into an estate, it produces two symmetrical mistakes: | Route | Reach | Reality | |---|---|---| | Vertical: root on an isolated bastion holding no data | Almost nothing | Impressive step, trivial consequence | | Horizontal: a peer build identity that can push to production | Everything | Unremarkable step, total consequence | The first is graded high because a boundary broke. The second is graded low because none did. Both gradings are wrong, and they are wrong in the same way: the route was scored instead of the reach. ## The framework declines to help you here MITRE ATT&CK files the use of a legitimate account as **T1078, Valid Accounts**, and lists that single technique under **four** tactics — Initial Access, Persistence, Privilege Escalation and Defense Evasion. The framework explicitly refuses to treat "they just used an account" as a lesser category of act; the same behaviour serves as the escalation *and* as the way the operator stays quiet. If your mental model says account use is a downgrade from escalation, the taxonomy everyone else uses already disagrees with you. ## The one thing the distinction still predicts It predicts what the step *depends on*. A vertical step depends on a defect or a misconfigured primitive that lives on a host, so it exists in one place and can be closed there. A horizontal step depends on two things that live somewhere else entirely: a reusable secret, and an entitlement somebody granted deliberately. That is a useful thing to know about the step. It is still not a severity claim. ## Answering this in a loop Give both definitions in one sentence each, then immediately volunteer the limit: the pair classifies the mechanism, and the interviewer's next question is almost always a scenario where the horizontal step is the catastrophic one. Say what severity actually follows from — what the final identity can act on, how cheaply the same route repeats, and how long it stays available — and you have answered the question they were really asking.

  • Give me a case where a purely horizontal step is worse than a vertical one.
    Root on a hardened bastion that stores nothing and reaches nothing is a vertical step with near-zero consequence. Taking over a peer build identity that is entitled to push images into production is horizontal, crosses no boundary at all, and hands the operator the objective. The route inverted the severity ordering completely.
  • Does MITRE ATT&CK treat 'they used a valid account' as something less than escalation?
    No. T1078 Valid Accounts is listed under Initial Access, Persistence, Privilege Escalation and Defense Evasion — the same technique serves all four purposes. The taxonomy deliberately does not carve out account use as a lesser act, which is exactly the point candidates miss when they downgrade a finding for lacking an escalation step.
  • If neither word measures impact, what should you state instead?
    State reach: name what the identity you ended on can read, write or trigger. Then state repeatability — whether the route needs an exploit or just custody of a credential — and durability, meaning how long the route stays open if nobody changes the entitlement. Those three describe consequence; horizontal and vertical describe only mechanism.

A burglar who picks the lock and one who finds the side door unlocked are standing in the same room. The story of how the door opened is not a measurement of what is in the room.

saying these in an interview costs you the question

  • Says horizontal movement is inherently less serious than vertical
  • Treats 'nobody became root or domain admin' as 'no real impact'
  • Assumes every environment has a privilege ladder to climb
  • Calls any gain in rights 'vertical' even between unrelated peer accounts
  • Cannot name what the final identity actually reaches

context

open as a page

Why can an operator with a domain admin credential run code on another host over the ADMIN$ share or WMI with no exploit?

level: juniorimportance: must knowfreq 70%

basics

~20 s

The administrative share and WMI are built-in remote-administration channels. They authenticate with the credential and run if the account has admin rights on the target, so no vulnerability is needed — the credential itself is the key.

open as a page

In Active Directory, why can any authenticated account read group memberships and permissions?

level: juniorimportance: must knowfreq 65%

basics

~10 s

Active Directory is a shared authorisation database, and Authenticated Users can read most attributes by default: memberships, owners, permission entries, service principal names. Any valid account can map who controls whom without touching anything.

open as a page

What separates credential stuffing from password spraying, and what does each operator already know?

level: juniorimportance: must knowfreq 78%

basics

~10 s

Stuffing replays real username-and-password pairs stolen from other sites and bets on reuse. Spraying knows no password at all: it tries one likely guess, such as Autumn2026!, against every account in a directory.

open as a page

With every user MFA-enrolled, how can one valid password still open a mailbox?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Enrolment is counted per user; enforcement is a property of each authentication path. A legacy mail protocol endpoint using basic authentication has no step in which a factor can be demanded, so the password alone succeeds there while the browser sign-in still challenges.

open as a page

What does a DCSync attack achieve, and why does it need no code on a domain controller?

level: juniorimportance: must knowfreq 55%

basics

~20 s

DCSync abuses Active Directory replication: with the right permissions an attacker asks a domain controller to send accounts' long-term password hashes, just as a peer controller would. Nothing runs on the controller, so it resembles ordinary replication.

open as a page

Why doesn't full-disk encryption stop a signed-in user copying credential files off a laptop?

level: juniorimportance: must knowfreq 62%

basics

~10 s

Full-disk encryption protects a powered-off volume. Once the machine is unlocked and someone is signed in, the volume key is loaded and every read is decrypted transparently, so credential files are ordinary readable files.

open as a page

What makes an Active Directory account 'roastable', and what does roasting one actually hand an attacker?

level: juniorimportance: must knowfreq 58%

basics

~20 s

An account is roastable if it carries a Service Principal Name or has Kerberos pre-authentication disabled. Either lets any ordinary user request material sealed with the account's password-derived key, which the attacker then cracks offline to recover the cleartext password.

open as a page

In an NTLM relay attack, why does the attacker never need the account's password?

level: juniorimportance: must knowfreq 58%

basics

~20 s

The coerced host computes the proof, not the attacker. The attacker sits between that host and a chosen service, forwards every authentication message unchanged, and the service grants the session to the attacker as that identity.

open as a page

Why is holding an identity-signing key different from stealing a password?

level: juniorimportance: must knowfreq 58%

basics

~20 s

A password makes you one user, presented to an issuer that decides whether to accept it. A signing key lets you mint any identity with any attributes, and the issuer decides nothing, because no authentication happens at all.

open as a page

Why can a stolen NT hash authenticate an attacker without ever being cracked?

level: juniorimportance: must knowfreq 72%

basics

~20 s

The protocol never sends a password. The client proves it holds the NT hash itself, so the hash is the credential. Anyone holding it authenticates directly, and cracking would only recover a plaintext that nothing in that path asks for.

open as a page

Why does reaching a host by RDP leave the operator's credential on that host, while remote service creation or WMI does not?

level: middleimportance: must knowfreq 58%

basics

~10 s

RDP is an interactive logon, which materialises the account's reusable secrets in memory on the target. Service creation and WMI use a network logon that authenticates and runs without leaving reusable credential material behind.

open as a page

Why doesn't a five-attempt account lockout stop a password spray across 8,000 accounts?

level: middleimportance: must knowfreq 72%

basics

~10 s

The counter is per account; the spray is per estate. One guess against each of 8,000 accounts leaves every counter at one, and the reset window clears it long before a second guess arrives.

open as a page

Why does one managed-service provider outprice any single client's domain administrator as a target?

level: middleimportance: must knowfreq 66%

basics

~20 s

Aggregation. One provider identity is already provisioned into every client it administers, so the cost of the second victim and the two-hundredth is a sign-in. That multiplier makes the provider worth spending on that no single client would ever attract.

open as a page

Which directory rights permit DCSync, and why is 'only Domain Admins can do this' wrong?

level: middleimportance: must knowfreq 50%

basics

~20 s

Two extended rights over the domain object grant it: DS-Replication-Get-Changes and DS-Replication-Get-Changes-All. Domain Admins hold them by default, but the rights are delegable and often sit on directory-sync connectors and backup accounts nobody counts as privileged.

open as a page

Why does a target service that enforces SMB signing break a relayed NTLM session?

level: middleimportance: must knowfreq 52%

basics

~20 s

Signing keys every message of the session with material derived from the account's secret. The relay operator forwarded the authentication without ever holding that secret, so the handshake completes and the session dies at the first signed request.

open as a page

A reviewer calls Active Directory enumeration 'read-only, not a vulnerability' — what is your rebuttal?

level: seniorimportance: must knowfreq 46%

basics

~20 s

The finding is not the read; it is the graph the read reveals. Because authorisation data is readable by design, an attacker computes a working two-hop route at zero cost, with no failed attempts and nothing modified, and then acts once.

open as a page

Which control class prices out a provider's standing delegated access when patching and MFA have not?

level: seniorimportance: must knowfreq 57%

basics

~20 s

Privilege lifetime and scope. The path needs a provider-controlled principal able to hold privilege in your tenant at the moment of use, so the controls that bite are approval-gated, time-boxed, least-role, per-client grants rather than anything about flaws or credential strength.

open as a page

Why is a provider's delegated tenant administration a way into your estate with no exploit anywhere?

level: juniorimportance: should knowfreq 54%

basics

~20 s

Delegated administration puts the provider's own engineers into your tenant's privileged roles. Anyone who reaches that provider signs in as an administrator you yourself granted, so nothing has to be broken, guessed or bypassed along the way.

open as a page

In an Active Directory or workload-identity estate, why is stepping sideways the same operation as stepping up?

level: middleimportance: should knowfreq 52%

basics

~20 s

Because authorisation there attaches to each identity as an unordered set of entitlements, with no enforced gap between peers. Every step, across or up, is the same act: obtain a credential and authenticate with it.

open as a page

Why does an operator prefer WMI or a WS-Man shell over creating a service on the ADMIN$ share to run code on a target?

level: middleimportance: should knowfreq 42%

basics

~20 s

WMI and a WS-Man shell invoke a management service already running and listening on the target, so nothing new must be written or installed. Service creation over the admin share requires writing an executable to the host and standing up a new service — more steps and more footprint.

open as a page

In Active Directory, a user in no privileged group still reaches Domain Admins — which rights explain it?

level: middleimportance: should knowfreq 52%

basics

~20 s

Membership is only one kind of edge. Ownership, WriteDacl, WriteOwner, GenericAll, write access to a group's member attribute and the force-password-reset extended right each let one principal take control of another, and inherited delegation spreads them across whole organisational units.

open as a page

Why does 90-day rotation with complexity rules make passwords easier to guess, not harder?

level: middleimportance: should knowfreq 62%

basics

~10 s

A human forced to invent a compliant password four times a year converges on a template: a season, the year, one capital, one symbol. That template is a short candidate list to spray.

open as a page

Why can an app password or a machine identity's client secret never present a second factor?

level: middleimportance: should knowfreq 46%

basics

~20 s

Neither has a human at the other end to prompt. An app password is issued as a substitute for the whole interactive flow the challenge lives in, and a machine identity authenticates with a secret alone. Both are separate credentials that outlive a user password rotation.

open as a page

A browser profile's saved logins and cookie store are copied to another machine — why are they inert?

level: middleimportance: should knowfreq 45%

basics

~20 s

The profile's secrets are sealed with a per-profile key that Windows DPAPI protects, and the DPAPI master key behind it is derived from the user's own logon password. Copied alone, the files decrypt to nothing.

open as a page

Why is a group-managed service account effectively immune to roasting while a human-set service password is cheap to crack?

level: middleimportance: should knowfreq 46%

basics

~20 s

Offline cracking cost scales with the password's keyspace. A group-managed service account uses a long, machine-generated random key whose keyspace is astronomically large; a short human-chosen password has a small keyspace a GPU rig exhausts in hours. The sealing algorithm only multiplies per-guess cost.

open as a page

If a relay target only accepts TLS, what does channel binding add that TLS alone does not?

level: middleimportance: should knowfreq 40%

basics

~20 s

TLS protects one hop, and the operator is a valid endpoint of two of them. The authentication inside names neither channel. Channel binding mixes the target's certificate into the response, so a reply minted over one channel is refused on the other.

open as a page

Which is wider: a stolen service key, a realm ticket-granting key, or a federation signing key?

level: middleimportance: should knowfreq 46%

basics

~20 s

The federation signing key is widest: it forges identity to every organisation that trusts the issuer. A realm's ticket-granting key covers every service inside one realm. A single service's own key covers only that service.

open as a page

Why is a leaked bcrypt password hash not reusable the way an NT hash is?

level: middleimportance: should knowfreq 48%

basics

~20 s

One word names two different objects. An application's bcrypt value is a checker: login submits a plaintext that is re-derived and compared, so the stored string cannot be submitted. A domain's NT hash is the credential the protocol accepts directly.

open as a page

After resetting a Kerberos service account's password, what still authenticates?

level: middleimportance: should knowfreq 52%

basics

~20 s

Tickets already issued for that identity keep working until their own expiry. The reset changes the long-term key, so a stolen keytab and the old NT hash stop being accepted, but an issued ticket is never rechecked against the current password.

open as a page

showing 1–30 of 50