Password Spraying
Methodology for performing password spraying attacks against active directory
This section contains some of my methodology and tips for performing password spraying attacks against Active Directory. Before spraying, I highly recommend that you first enumerate the password policy on the domain so that you don't lock out accounts.
If you are looking to password spray external services to gain initial access, refer to the Fortress section of this GitBook.
Get List of Users
Spraying
Password List
These passwords were referenced from the published Conti manual and often work. This should be an unspoken rule, but ensure that your list is tailored for each engagement (year, month, etc).
References
Last updated