What is password spraying?¶
Password spraying is trying one or a few likely passwords across many accounts rather than repeatedly attacking one account.
The pattern matters because it is often designed to reduce lockouts and avoid obvious high-volume failure against a single user.
Look at the whole authentication period¶
A spraying pattern may show:
- many different usernames;
- one or a small number of passwords;
- low request rate;
- regular spacing;
- repeated source infrastructure;
- similar application/user-agent;
- one or more later successes.
A useful pattern might look like:
One failure tells you very little. The broad pattern is the evidence.
Compare with legitimate service behaviour¶
Repeated failures across several accounts can also come from:
- misconfigured applications;
- old stored credentials;
- scheduled services;
- monitoring tools;
- automated administration.
So check:
- timing;
- account set;
- common password pattern where safely available;
- application/client;
- known service behaviour;
- source infrastructure.
A success does not tell you how the password became valid¶
If one account succeeds after the spray, that supports successful authentication.
It does not automatically prove:
- the attacker discovered the password by guessing;
- who controlled the source infrastructure;
- who used the account afterwards.
Follow the successful session into later activity.
The practical point is: password spraying is a many-account, low-volume authentication pattern. Prove the pattern first, then treat any successful account as a separate attribution and control question.