Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is password spraying?

Password spraying is trying one or a few likely passwords across many accounts rather than repeatedly attacking one account.

The pattern matters because it is often designed to reduce lockouts and avoid obvious high-volume failure against a single user.

Look at the whole authentication period

A spraying pattern may show:

  • many different usernames;
  • one or a small number of passwords;
  • low request rate;
  • regular spacing;
  • repeated source infrastructure;
  • similar application/user-agent;
  • one or more later successes.

A useful pattern might look like:

Example authentication pattern
09:00 · alice · failed09:03 · beth · failed09:06 · chris · failed09:09 · david · successApplication: web loginSource group: same hosting range

One failure tells you very little. The broad pattern is the evidence.

Compare with legitimate service behaviour

Repeated failures across several accounts can also come from:

  • misconfigured applications;
  • old stored credentials;
  • scheduled services;
  • monitoring tools;
  • automated administration.

So check:

  • timing;
  • account set;
  • common password pattern where safely available;
  • application/client;
  • known service behaviour;
  • source infrastructure.

A success does not tell you how the password became valid

If one account succeeds after the spray, that supports successful authentication.

It does not automatically prove:

  • the attacker discovered the password by guessing;
  • who controlled the source infrastructure;
  • who used the account afterwards.

Follow the successful session into later activity.

The practical point is: password spraying is a many-account, low-volume authentication pattern. Prove the pattern first, then treat any successful account as a separate attribution and control question.

Reference: CIM-047Cyber Incidents & Offender Methods