1200KM / simulation
T1110.003 Password Spraying — Attack Simulation
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when…
Technique description
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Password Spray (DomainPasswordSpray)
Procedure 263ae743-515f-4786-ac7d-41ef3a0d4b2b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - DomainPasswordSpray Attacks
Procedure 5ccf4bbd-7bf6-43fc-83ac-d9e38aff1d82; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Password Spray all Domain Users
Procedure 90bc2e54-6c84-47a5-9439-0a2a92b4b175; elevation not declared required; cleanup not declared. Not executed or individually validated.
- AWS - Password Spray an AWS using GoAWSConsoleSpray
Procedure 9c10d16b-20b1-403a-8e67-50ef7117ed4e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Password spray all Azure AD users with a single password
Procedure a8aa2d3e-1c52-4016-bc73-0f8854cfa80a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Password Spray Invoke-DomainPasswordSpray Light
Procedure b15bc9a5-a4f3-4879-9304-ea0011ace63a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Password Spray using Kerbrute Tool
Procedure c6f25ec3-6475-47a9-b75d-09ac593c5ecb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Password spray all Active Directory domain users with a single password via LDAP against domain controller (NTLM or Kerberos)
Procedure f14d956a-5b6e-4a93-847f-0c415142f07d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Password Spray Microsoft Online Accounts with MSOLSpray (Azure/O365)
Procedure f3a10056-0160-4785-8744-d9bd7c12dc39; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.