Esc
Password Spraying - T1110.003
(ATT&CK® Technique)
Definition
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.