Password Spray
Last updated
Last updated
Accounts can be locked during the process. Always check the password policy before starting the attack.
Checking password policy is important for creating a sufficient wordlist. also, it is important to look for the Lockout threshold in order to avoid account lockouts during the brute-force.
Retrieve the password policy:
using NetExec:
If valid usernames are known, perform a password spray to find weak passwords:
Another method to spray passwords, particularly targeting various services:
kerbrute
nxc