The playbookspraying · low and slow brute force

Password spraying

Trying one common password against many accounts, rather than many passwords against one. Each account sees a single failed attempt, which is below the threshold that would lock it or raise an alert.

Why it matters to you

Per account lockout is the control this technique is designed around, and having it does not help. The signal is horizontal: one password, one source, many usernames, all just under the limit. If your alerting is scoped to a single account it cannot see the attack by construction.

Where we meet it

The password list is not guessed, it is bought. Combolists sorted by locale and by sector circulate for exactly this, which is why the sprayed password often looks oddly specific to the target's country or industry.

Where this term stops being vocabulary

Sherlog is where you watch it happen to you

Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.