skip to content

From One Account Outward

How one working account becomes the estate: reading the directory for the route, moving sideways as often as upward, and using the channels operations already runs on. Interviewers make you walk it.

on this pageshow

explore

questions

12

What separates horizontal from vertical privilege movement, and what does neither measure?

level: juniorimportance: must knowfreq 70%

answer

  1. route taken, not damage done
  2. boundary crossed versus credential presented
  3. a peer can hold far more than you
  4. ladders are a single-host idea
  5. ATT&CK files account use under four tactics

basics

~20 s

Vertical movement acquires rights an identity lacks; horizontal movement takes over a peer identity holding different rights. Both describe the route, not the damage. A sideways step onto an identity that already owns production ends the intrusion.

solid answer

~50 s

Vertical movement means the identity you control gains rights it did not have, crossing a boundary the system was built to enforce. Horizontal movement means you stop using that identity and start using another one of comparable standing, by presenting its credential. The distinction describes the mechanism of the step, and it gets routinely mistaken for a measure of seriousness. It is not. What matters is what the identity you end up holding can reach. If a peer service account already holds production database rights, moving sideways onto it is the whole objective, with no boundary crossed anywhere. In practice the two collapse: an operator does not care whether the next credential belongs to something nominally above them, only whether it carries the entitlement they want. Treat `no privilege escalation occurred` as a statement about technique, never as a statement about impact.

go deeper

for a junior

Be ready to define both terms in one sentence each and to say plainly that they describe the route, not the harm. Knowing that a sideways step can be the end of the story is what the screener is checking.

for a middle

An interviewer expects you to explain why the ladder is a single-host idea and why a directory has no rungs, then show the mechanism is identical in both cases: get a credential, present it.

for a senior

Demonstrate that you grade by reach, repeatability and durability rather than by which word applies. Bring a concrete inversion — a high-privilege step that reached nothing next to a peer step that reached production.

for a principal

Own the consequence for how work is prioritised: if the vocabulary drives severity, an estate systematically under-rates the routes that need no defect at all and over-rates the ones a host fix closes.

## The two words **Vertical privilege movement** (usually called privilege escalation) means the identity currently under an operator's control ends up with rights it did not have. Something the system actively enforces gets crossed: an unprivileged Windows token becomes an administrative one, a non-root Linux process becomes uid 0, an application account that could read becomes one that can write. **Horizontal privilege movement** means control passes to a *different* identity of comparable standing. Nothing is elevated. The operator simply stops authenticating as A and starts authenticating as B, because they now hold something B can authenticate with. That is the whole distinction, and it is a distinction about **how the step was taken**, not about how much the step reached. ## Where the distinction is genuinely real On a single machine. An operating system kernel maintains an enforced gap between an unprivileged context and a privileged one, and that gap is a designed boundary with a designed guard. The same is true inside a single application that checks a role before an action. In those places "up" is well defined, because someone drew the ladder and wrote code to police it. ## Where it stops being real In a directory, or in a workload-identity estate, authorisation attaches to each identity as a *set of entitlements*, and those sets are not ordered. There is no rung above another rung. "Administrator" is not a level; it is an identity with an unusually generous set attached. Two peer accounts may hold wildly different power with no enforced boundary between them, because there is no boundary to enforce, only two separate credentials. So in that environment the two movements are the same operation: obtain a credential and present it. The result differs only in what the new identity happens to hold. ## What an operator is actually optimising Not rank. **Reach, per unit of cost.** The question an operator asks about the next identity is "does it already hold the entitlement I need, and how cheaply can I get something that authenticates as it?" A top-tier administrative credential is expensive to obtain and heavily watched; a build identity or a workload identity is often neither, and frequently holds more of what the objective requires. Choosing the cheap peer over the expensive superior is ordinary economics, not a compromise on ambition. ## Why the severity error is so common Because the vocabulary came from single-machine security, where the ladder was real and climbing it *was* the achievement. Carried into an estate, it produces two symmetrical mistakes: | Route | Reach | Reality | |---|---|---| | Vertical: root on an isolated bastion holding no data | Almost nothing | Impressive step, trivial consequence | | Horizontal: a peer build identity that can push to production | Everything | Unremarkable step, total consequence | The first is graded high because a boundary broke. The second is graded low because none did. Both gradings are wrong, and they are wrong in the same way: the route was scored instead of the reach. ## The framework declines to help you here MITRE ATT&CK files the use of a legitimate account as **T1078, Valid Accounts**, and lists that single technique under **four** tactics — Initial Access, Persistence, Privilege Escalation and Defense Evasion. The framework explicitly refuses to treat "they just used an account" as a lesser category of act; the same behaviour serves as the escalation *and* as the way the operator stays quiet. If your mental model says account use is a downgrade from escalation, the taxonomy everyone else uses already disagrees with you. ## The one thing the distinction still predicts It predicts what the step *depends on*. A vertical step depends on a defect or a misconfigured primitive that lives on a host, so it exists in one place and can be closed there. A horizontal step depends on two things that live somewhere else entirely: a reusable secret, and an entitlement somebody granted deliberately. That is a useful thing to know about the step. It is still not a severity claim. ## Answering this in a loop Give both definitions in one sentence each, then immediately volunteer the limit: the pair classifies the mechanism, and the interviewer's next question is almost always a scenario where the horizontal step is the catastrophic one. Say what severity actually follows from — what the final identity can act on, how cheaply the same route repeats, and how long it stays available — and you have answered the question they were really asking.

  • Give me a case where a purely horizontal step is worse than a vertical one.
    Root on a hardened bastion that stores nothing and reaches nothing is a vertical step with near-zero consequence. Taking over a peer build identity that is entitled to push images into production is horizontal, crosses no boundary at all, and hands the operator the objective. The route inverted the severity ordering completely.
  • Does MITRE ATT&CK treat 'they used a valid account' as something less than escalation?
    No. T1078 Valid Accounts is listed under Initial Access, Persistence, Privilege Escalation and Defense Evasion — the same technique serves all four purposes. The taxonomy deliberately does not carve out account use as a lesser act, which is exactly the point candidates miss when they downgrade a finding for lacking an escalation step.
  • If neither word measures impact, what should you state instead?
    State reach: name what the identity you ended on can read, write or trigger. Then state repeatability — whether the route needs an exploit or just custody of a credential — and durability, meaning how long the route stays open if nobody changes the entitlement. Those three describe consequence; horizontal and vertical describe only mechanism.

A burglar who picks the lock and one who finds the side door unlocked are standing in the same room. The story of how the door opened is not a measurement of what is in the room.

saying these in an interview costs you the question

  • Says horizontal movement is inherently less serious than vertical
  • Treats 'nobody became root or domain admin' as 'no real impact'
  • Assumes every environment has a privilege ladder to climb
  • Calls any gain in rights 'vertical' even between unrelated peer accounts
  • Cannot name what the final identity actually reaches

context

open as a page

Why can an operator with a domain admin credential run code on another host over the ADMIN$ share or WMI with no exploit?

level: juniorimportance: must knowfreq 70%

basics

~20 s

The administrative share and WMI are built-in remote-administration channels. They authenticate with the credential and run if the account has admin rights on the target, so no vulnerability is needed — the credential itself is the key.

open as a page

In Active Directory, why can any authenticated account read group memberships and permissions?

level: juniorimportance: must knowfreq 65%

basics

~10 s

Active Directory is a shared authorisation database, and Authenticated Users can read most attributes by default: memberships, owners, permission entries, service principal names. Any valid account can map who controls whom without touching anything.

open as a page

Why does reaching a host by RDP leave the operator's credential on that host, while remote service creation or WMI does not?

level: middleimportance: must knowfreq 58%

basics

~10 s

RDP is an interactive logon, which materialises the account's reusable secrets in memory on the target. Service creation and WMI use a network logon that authenticates and runs without leaving reusable credential material behind.

open as a page

A reviewer calls Active Directory enumeration 'read-only, not a vulnerability' — what is your rebuttal?

level: seniorimportance: must knowfreq 46%

basics

~20 s

The finding is not the read; it is the graph the read reveals. Because authorisation data is readable by design, an attacker computes a working two-hop route at zero cost, with no failed attempts and nothing modified, and then acts once.

open as a page

In an Active Directory or workload-identity estate, why is stepping sideways the same operation as stepping up?

level: middleimportance: should knowfreq 52%

basics

~20 s

Because authorisation there attaches to each identity as an unordered set of entitlements, with no enforced gap between peers. Every step, across or up, is the same act: obtain a credential and authenticate with it.

open as a page

Why does an operator prefer WMI or a WS-Man shell over creating a service on the ADMIN$ share to run code on a target?

level: middleimportance: should knowfreq 42%

basics

~20 s

WMI and a WS-Man shell invoke a management service already running and listening on the target, so nothing new must be written or installed. Service creation over the admin share requires writing an executable to the host and standing up a new service — more steps and more footprint.

open as a page

In Active Directory, a user in no privileged group still reaches Domain Admins — which rights explain it?

level: middleimportance: should knowfreq 52%

basics

~20 s

Membership is only one kind of edge. Ownership, WriteDacl, WriteOwner, GenericAll, write access to a group's member attribute and the force-password-reset extended right each let one principal take control of another, and inherited delegation spreads them across whole organisational units.

open as a page

An operator buys a valid CI pipeline token, pushes an image the cluster deploys, and reads production data. Which step escalated privilege?

level: seniorimportance: should knowfreq 45%

basics

~20 s

None of them. The token was entitled to push, the cluster was configured to pull and run whatever it finds, and the workload identity already held the database rights. The operator's only cost was acquiring one credential.

open as a page

Why is a single desktop-deployment credential a wider attack channel than a domain administrator account across 900 stores?

level: seniorimportance: should knowfreq 40%

basics

~20 s

The deployment path is built to push code to every host at once and its agent already listens on each one. Whoever holds its credential gets one-operation code execution estate-wide, while a domain admin must still reach each host through some channel.

open as a page

After a merger adds a forest trust, why does the privilege graph change with no membership edits?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

A trust is an edge. Principals from the acquired forest become authenticated principals in yours when they authenticate across it, and any group or permission entry that references them joins the two graphs, so their weakest delegation now leads into your estate.

open as a page

A reviewer wants a production-reach finding closed as low because no privilege was escalated. What do you argue?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Argue reach, class, cost and durability instead of boundaries. Concede honestly that nothing is unpatched, which changes who owns the fix rather than how serious it is — a route needing no defect has no vendor timeline slowing it down.

open as a page