Password spraying still works: defending the front door
Ask any red teamer what gets them in most often and the answer is rarely a zero-day. It's a weak password, sprayed carefully against an exposed login. Password spraying has been around for years, and it still works — because the defences most organisations rely on were designed for a different attack.
How spraying differs from brute force
Brute force hammers one account with many passwords and trips account lockout almost immediately. Spraying inverts it: one password, like Winter2020!, tried once against every account, then a pause, then the next password. No single account sees more than a handful of attempts, so lockout thresholds never fire. Across a few thousand users, someone always picked the season and the year.
Where attackers spray
- Exposed webmail and SSO portals — OWA, Microsoft 365, ADFS, any login reachable from the internet.
- VPN gateways — often without MFA, and a direct route onto the internal network.
- Internal SMB/LDAP — once an attacker has a foothold, spraying the domain is quick and quiet.
Usernames come from the same place every time: LinkedIn, breach corpora, and the predictable first.last@ format most companies use. Building a target list is reconnaissance, not hacking.
How to shut it down
- MFA everywhere external. The single highest-value control. Spraying lands a password; MFA stops it becoming access. Prefer phishing-resistant factors.
- Ban weak and seasonal passwords. Screen new passwords against breach lists and obvious patterns.
Companyname1andAutumn2020!should be impossible to set. - Watch for the pattern, not the count. Lockout won't fire, so alert instead on many accounts failing with the same password in a short window — the unmistakable signature of a spray.
- Smart lockout and geo/velocity controls. Cloud identity providers offer these; turn them on and tune them.
Spraying is a numbers game that rewards patience. You win by making the numbers bad: no weak passwords to find, MFA behind every door, and an alert the moment someone starts counting.
The MFA gap attackers look for
MFA is the control, but attackers have learned exactly where it isn’t. Legacy mail protocols (IMAP, POP and SMTP with basic auth) often bypass modern MFA entirely; service and break-glass accounts get quietly exempted “just for now”; and where push-based MFA is used, attackers simply spray a known password and then bomb the victim with prompts until one is accepted out of fatigue. Disable legacy authentication, bring every account — including service accounts — under MFA, and prefer number-matching or phishing-resistant factors over a plain push.
After the spray: what one password buys
A single valid credential is rarely the finish line — it’s the starting gun. From one mailbox an attacker reads internal conversation, sets forwarding rules, finds the VPN instructions, and sprays again from the inside where defences are weaker. Assume one account will fall, and design so that it buys the attacker as little as possible: MFA on everything, least privilege, and alerting on the first sign of internal reconnaissance.
How spraying slips past smart lockout
Smart lockout and velocity controls raise the cost of spraying, but they do not end it. The whole premise of a spray is patience, and an attacker who treats detection thresholds as a budget rather than a wall will simply spend slowly. Understanding the shape of that evasion, conceptually, is what lets a defender tune for it.
- Low-and-slow timing. Instead of many attempts per minute, the attacker tries one password against each account and then waits hours or days before the next round, staying under per-account and per-tenant counters that reset on a rolling window.
- Jitter. Randomised gaps between attempts break the fixed-interval signature that simple rules key on, so the traffic never forms the neat periodic pattern a naive detector expects.
- Source rotation. Spreading attempts across many residential or cloud egress addresses defeats per-IP throttling, because no single source ever crosses a threshold. The failures are only visible when you count across the identity, not the address.
- Account spreading. A single guess fanned across thousands of usernames keeps every individual account below its lockout limit while still testing one popular password against the whole directory.
How defenders detect/stop this
Correlate on the identity and the tenant, not the source address. A horizontal pattern — one password, many accounts, many IPs — is invisible per-IP but obvious when failed authentications are aggregated over a long window. Extend detection windows to days so low-and-slow campaigns accumulate into a visible signal, and alert on the ratio of distinct accounts touched per source rather than raw attempt counts.
Legacy and basic-auth protocols that walk around MFA
The most reliable way past MFA is to use a door that never learned to ask for it. Older authentication paths — legacy mail protocols, basic authentication endpoints, and certain app-password mechanisms — authenticate with a username and password alone and cannot present a second-factor challenge. A spray that finds a valid credential and then replays it through one of these paths inherits a logged-in session without ever touching the MFA prompt. This is why organisations with strong MFA on the web portal still suffer account takeover: the credential was correct, and the attacker simply chose the protocol that could not enforce the policy.
How defenders detect/stop this
- Disable legacy and basic authentication tenant-wide and move all clients to modern, token-based flows that are subject to policy. Treat any remaining legacy endpoint as an unguarded entrance.
- Where a protocol genuinely cannot be retired, fence it with an allow-list of known addresses and alert on every authentication through it.
- Audit app passwords and per-application secrets; they are frequently the quiet exemption that undermines an otherwise sound rollout.
Phishing-resistant MFA: why FIDO2 and passkeys change the maths
Not all second factors are equal. One-time codes and push approvals confirm that someone holds a secret or tapped a button, but they can be relayed: an attacker-in-the-middle proxy can capture a code or harvest the approval of a tired user. FIDO2 and passkeys are phishing-resistant because the authentication is cryptographically bound to the legitimate origin. The private key never leaves the authenticator, and a signature produced for a rogue domain is worthless, so a relayed or replayed credential simply does not authenticate. For spraying specifically, this matters because even a correctly guessed password yields nothing without the bound key.
How defenders detect/stop this
Prioritise WebAuthn/FIDO2 or passkeys for privileged and high-risk roles, and treat OTP and push as fallbacks to be minimised, not endpoints to be trusted. Where push remains, enforce number-matching and contextual detail to blunt approval fatigue, and alert on repeated denied or rapid-fire approval prompts as a sign of active abuse.
Conditional access, risk signals and detection engineering
The final layer is to stop evaluating authentication as a single pass/fail and start scoring it. Conditional access weighs signals — device compliance, managed status, network, geography, user and sign-in risk — and steps up to a stronger challenge or blocks outright when the picture looks wrong. A sign-in that is credential-correct but anomalous should still have to prove itself. Detection engineering then turns the telemetry into alerts that a human can act on.
How defenders detect/stop this
- Failed-auth-across-accounts: count distinct usernames failing against the same password or source over a rolling window — the canonical spray signature.
- Impossible travel: successful sign-ins from geographically distant locations within an implausible interval.
- New-ASN and anonymiser sign-ins: first-seen hosting providers, VPNs or anonymising networks for an account, especially straight after a burst of failures.
- Feed these into risk-based conditional access so a risky sign-in is challenged or denied automatically, not merely logged for later.
How exposed is your front door?
A penetration test or red team will spray your real perimeter — safely — and show you exactly which accounts and portals give way.
Scope a test