password-spray-methodology
Installation
SKILL.md
Password Spray Methodology
Password spraying is the highest-ROI credential attack: one (or few) passwords tried against many users. It's quiet, avoids lockouts, and succeeds where traditional brute force fails. This skill consolidates every spray vector, enumeration technique, pattern, and protocol across the entire skill catalog.
This is a methodology skill. Protocol-specific details live in their respective skills — cross-reference them for deep dives. This skill covers the universal spray pipeline that applies everywhere.
When to Use
- Starting ANY engagement with a user list but no credentials
- Finding internet-facing login portals (OWA, Okta, ADFS, VPN, SSO, OIDC)
- After
hunt-ntlm-inforeveals AD domain/UPN format — feed into spray - After
hunt-ldapenumerates sAMAccountNames — feed into spray - After
js-secrets-extractionfinds email patterns — feed into spray - OneDrive 302/404 enum (from
m365-entra-attack) confirms licensed users — spray them - Any leaked credential dump from client — validate against all services
- Active-attacker detection via Smart Lockout differential