Password spraying

intermediateExternal & Wireless

TL;DR

Password spraying tries one common password against many accounts, so it slips under per-account lockout thresholds. It works depressingly often against exposed logins without MFA. The defences are MFA, monitoring for the pattern, and sensible lockout.

What it is

Instead of hammering one account with many passwords (which locks it out), spraying tries a single likely password — a seasonal one, the company name and a year — across a whole list of users. Low and slow, it stays under the radar.

How it works

Given a list of valid usernames (often from OSINT) and an exposed login — a webmail portal, a VPN, a cloud tenant — the attacker tries one password per account, waits, and tries the next. Somewhere in a big enough org, someone is using the obvious one.

How to detect it

How to defend

← Back to External & Wireless