Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do valid accounts and native tools make…
Threats, Abuse & Incident Response

Why do valid accounts and native tools make lateral movement so hard to stop?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Threats, Abuse & Incident Response

They collapse the difference between administrator activity and attacker activity. Native tools such as PowerShell, WMI, RDP, and SSH are already trusted in many environments, and valid credentials let the attacker ride that trust without malware. The risk rises when permissions are excessive and east-west paths are left open by default.

Why valid accounts and native tools are so effective for lateral movement

Attackers do not need to “break in” again if they already have credentials that the environment accepts and tools the environment allows. That makes the activity look operational rather than malicious. The real issue is not just access, but the combination of trusted logins, remote admin protocols, and internal paths that were never segmented tightly enough to distinguish routine administration from hostile use.

Because native tooling is already part of normal IT operations, defenders often inherit a detection problem as much as a prevention problem. PowerShell, WMI, RDP, SSH, and similar mechanisms can be used for legitimate administration, so alerts based only on tool name create noise. The harder question is whether the account, source host, timing, and command pattern fit normal administrator behaviour.

Valid credentials also flatten the attacker’s tradecraft. Once an attacker can authenticate as a real user or service, they can often enumerate shares, query directory data, reach management planes, and move through east-west paths without dropping obvious malware. That is why excessive permissions, reused credentials, and flat network design turn a single foothold into broad internal reach.

What makes trusted tools and valid logins so difficult to distinguish from admin activity?

Most enterprise environments were designed to let administrators do work quickly. Remote management, scripting, and authenticated shell access are therefore expected behaviours, especially in Windows and hybrid environments. When those same capabilities are available to an attacker, the defender has to judge intent from context, not from the mere presence of the tool.

Native tools also blend into ordinary telemetry because they use approved channels, signed binaries, and built-in protocol paths. A remote PowerShell session, an SSH login, or a WMI request can all be perfectly normal. The decisive signals are usually abnormal combinations: unusual workstation-to-server paths, access to systems the account never touches, or command sequences that are inconsistent with the user’s role.

Valid accounts make this worse because they inherit trust, permissions, and sometimes existing sessions or tokens. If privileged access is overbroad, the attacker does not need to escalate immediately. They can often discover where the high-value systems are, then reuse the organisation’s own trust relationships to reach them.

Why east-west exposure turns a single compromise into a movement problem

Inside a network, lateral movement depends on what remains reachable after the first login. If internal segmentation is weak, one valid account can reach file servers, admin endpoints, directory services, backup systems, and management interfaces that were never meant to be broadly accessible. The attacker’s job becomes simple: follow allowed paths until they find a better one.

That is why “default internal trust” is such a common failure mode. If east-west traffic is broadly open, any authenticated user becomes a potential launch point for deeper access. The same is true when administrative shares, remote desktop, or scripting remoting are left available far beyond the teams that actually need them.

Once inside, attackers often prefer tools that avoid tripping obvious malware controls. They rely on what the environment already permits, which means the security boundary has to sit around identity, privilege, and reachability rather than around software reputation alone. A valid session can be more dangerous than a suspicious executable when the network trusts it too much.

Risk and Threat Considerations

Valid accounts and native tools create a high-confidence abuse path because the attacker can behave like a legitimate operator while still pursuing theft, persistence, or destructive access. The main risk is not just initial compromise, but the speed with which trusted access can be converted into broad internal exposure when privileges and lateral routes are too open.

Failure mechanism: The environment treats authenticated activity and sanctioned remote administration as normal, so the attacker uses accepted credentials and built-in tools to traverse systems without introducing a clear malware signal.

Impact: Detection becomes slower, containment becomes harder, and a single compromised account can reach many more assets than the original access point should have allowed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1021 — Remote ServicesValid accounts and native tools enable remote internal movement through trusted admin channels.
T1059 — Command and Scripting InterpreterPowerShell and similar native tools are core mechanisms for living-off-the-land lateral movement.
T1078 — Valid AccountsThe question centers on attacker use of trusted credentials to blend in as legitimate activity.
Recommendation — Map remote admin activity to T1021 and monitor unusual internal access paths and session patterns. Hunt for suspicious script execution and constrain interpreter use to approved admin workflows. Track anomalous use of valid accounts and flag impossible or out-of-role internal access.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeExcessive permissions are what turn a valid login into broad internal reach.
IA-2 — Identification and Authentication (Organizational Users)Trusted logins are the entry condition that attackers abuse for lateral movement.
SC-7 — Boundary ProtectionEast-west reachability and weak internal segmentation enable movement after first access.
Recommendation — Restrict each account to the minimum privileges needed for its administrative role. Enforce strong authentication for administrative access and monitor for anomalous logins. Segment internal networks so compromised accounts cannot freely reach adjacent systems.

Practitioner Guidance

What to prioritise: Focus first on the combination of privilege scope and path reachability. If an account can authenticate broadly and the network allows broad east-west access, the movement problem is already present even before you look at indicators of compromise.

What to verify: Confirm which accounts are allowed to use PowerShell, WMI, RDP, SSH, and similar native mechanisms, then check whether those allowances match the actual operational need. Also verify that admin access is coming from approved hosts and is constrained to the smallest practical target set.

Decision rule: If the account can access production systems and the source path is not tightly bounded, treat the issue as a containment and privilege problem first, not just a monitoring problem. Alert tuning helps, but it does not replace segmentation, least privilege, and administrative tiering.

Practitioner takeaway: The defender’s real task is to make legitimate administration provably narrow and observable, because once valid access and native tools are both available, “normal” and “hostile” can look nearly identical.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org