← All walkthroughs

Password spraying to a cloud mailbox

A low-and-slow password spray against a cloud identity provider lands a valid login, defeats weak MFA, and reaches email and cloud roles — an identity-first attack path.

Cloud identity / M365-style tenant Intermediate IdentityCloudMFA
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

An authorized assessment of a cloud tenant's identity exposure. You may test the published authentication portals against an agreed user list. The objective is to show whether credential-guessing plus MFA weaknesses lead to mailbox and cloud access.

Practice this path: Cloud attacks · MITRE ATT&CK
  1. 1

    Reconnaissance

    Build the user list and naming scheme

    Determine the email/username format and assemble an in-scope list of valid accounts to target, keeping strictly to the approved users.

    Detection

    Account-enumeration probing against the login/autodiscover endpoints is visible in sign-in telemetry.

    Mitigation

    Reduce username-enumeration signals, and monitor authentication endpoints for enumeration patterns.

  2. 2

    Credential Access

    Spray a small number of likely passwords

    Try one or two common/seasonal passwords across the whole user list with long delays, staying under lockout thresholds — the essence of spraying versus brute force.

    Detection

    Many accounts each seeing a single failed login from one source in a short window is the classic spray signature.

    Mitigation

    Ban common passwords, enforce smart lockout, require phishing-resistant MFA, and alert on spray patterns.

  3. 3

    Credential Access / Defense Evasion

    Get past weak MFA

    Where a sprayed credential is valid but MFA is enabled, assess whether push-notification fatigue or a weak second factor allows access — reporting MFA strength as a finding rather than coercing a real user.

    Detection

    Bursts of MFA push requests to one user, and approvals at odd hours, are detectable; number-matching MFA defeats fatigue.

    Mitigation

    Use phishing-resistant MFA (FIDO2), enable number matching, and alert on repeated push prompts.

  4. 4

    Collection

    Access the mailbox

    With a valid session, demonstrate read access to the compromised user's cloud mailbox, documenting the exposure (sensitive mail, delegation, rules) rather than harvesting content.

    Detection

    Mailbox sign-ins from new locations/clients and new inbox rules are visible in audit logs.

    Mitigation

    Conditional-access by device/location, disable legacy auth, and alert on new mail-forwarding rules.

  5. 5

    Privilege Escalation / Persistence

    Expand access across the tenant

    Assess whether the foothold identity can grant itself additional mailbox delegation or cloud roles, demonstrating how one mailbox becomes broader tenant access.

    Detection

    New delegate permissions and role assignments are high-value audit events.

    Mitigation

    Least-privilege roles, approval workflows for role changes, and monitoring of delegation grants.

Key takeaways

  • Identity is the new perimeter: a weak password plus weak MFA beats the firewall entirely.
  • Spraying stays under lockout thresholds — detect it by the fan-out across many accounts, not failures per account.
  • Phishing-resistant MFA and conditional access break this path at the MFA and mailbox stages.