CAPEC 565 Password Spraying

Draft Detailed High Risk
Severity High

Description

{'xhtml:p': 'In a Password Spraying attack, an adversary tries a small list (e.g. 3-5) of common or expected passwords, often matching the target's complexity policy, against a known list of user accounts to gain valid credentials. The adversary tries a particular password for each user account, before moving onto the next password in the list. This approach assists the adversary in remaining undetected by avoiding rapid or frequent account lockouts. The adversary may then reattempt the process with additional passwords, once enough time has passed to prevent inducing a lockout.'}

Attack Execution Flow

3

Mitigations

3

Consequences

Indicators

3

Relationships

Related ATT&CK Techniques

1

Resources Required

3