Ad Password Spraying

Active Directory password spraying and brute force methodology for authorized security assessments. Use this skill when conducting penetration tests, red team operations, or security audits on Active Directory environments where you have explicit written authorization. Covers password policy enumeration, spraying techniques with various tools (NetExec, kerbrute, Rubeus, SpearSpray), SAMR password change exploitation, and OWA/Google/Okta spraying. Make sure to use this skill whenever the user mentions password spraying, credential testing, AD brute force, or needs to enumerate valid credentials in an AD environment.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/windows-hardening/active-directory-methodology/password-spraying commit cdc157129a

Frequently asked questions

npx skillmds@latest add abelrguezr/ad-password-spraying