password-spray-methodology

Installation
SKILL.md

Password Spray Methodology

Password spraying is the highest-ROI credential attack: one (or few) passwords tried against many users. It's quiet, avoids lockouts, and succeeds where traditional brute force fails. This skill consolidates every spray vector, enumeration technique, pattern, and protocol across the entire skill catalog.

This is a methodology skill. Protocol-specific details live in their respective skills — cross-reference them for deep dives. This skill covers the universal spray pipeline that applies everywhere.

When to Use

  • Starting ANY engagement with a user list but no credentials
  • Finding internet-facing login portals (OWA, Okta, ADFS, VPN, SSO, OIDC)
  • After hunt-ntlm-info reveals AD domain/UPN format — feed into spray
  • After hunt-ldap enumerates sAMAccountNames — feed into spray
  • After js-secrets-extraction finds email patterns — feed into spray
  • OneDrive 302/404 enum (from m365-entra-attack) confirms licensed users — spray them
  • Any leaked credential dump from client — validate against all services
  • Active-attacker detection via Smart Lockout differential

Universal Spray Pipeline (5 Phases)

Installs
11
GitHub Stars
1.2K
First Seen
Jul 9, 2026
password-spray-methodology — uphiago/recon-skills