{"repo":"TheresAFewConors/MSSprinkler","free":true,"listed":false,"github":"https://github.com/TheresAFewConors/MSSprinkler","clone":"git clone https://github.com/TheresAFewConors/MSSprinkler.git","description":"MSSprinkler is a password spraying utility for organizations to test their Microsoft Online accounts from an external perspective. It employs a 'low-and-slow' approach to avoid locking out accounts, and provides verbose information related to accounts and tenant information.","language":"PowerShell","stars":79,"topics":["offensive-security","password","passwordspray","passwordspraying","powershell","powershell-module","redteam"],"license":"MIT","category":"cli-tools","readme_excerpt":"MSSprinkler Overview MSSprinkler is a password spraying utility for organizations to test their Microsoft Online accounts from an external perspective. It employs a 'low-and-slow' approach to avoid locking out accounts, and provides verbose information related to accounts and tenant information. Contents - Description - Current Feature - Installation - Help - Disclaimer Description MSSprinkler is written in PowerShell and can be imported directly as a module. It has no other dependencies. MSSprinkler relies on the verbose error messaging provided by Microsoft to identify additional information beyond standard password spray success or failed authentication attempts, which allows for the gathering of additional information related to the user account. MSSprinkler also allows for a configurable threshold to prevent locking out accounts by mistake. By default, this is set to 8 (n-2 under Microsoft's default) however this can be adjusted based on the organizations lockout policy. Additionally, successful sign-in to an account with MFA enabled will not produce an MFA push to the user, allowing for non-disruptive information gathering. Current Features - Automatically spray a list of Microsoft Online accounts with a password list. - Automatically retrieve and log the tenant ID associated with the domain and store in JSON format. - Stored under /jsonModules/domainCache.json - Automatically retrieve the access & refresh tokens for successful user sign-ins, providing long-term persist","default_branch":null,"files":null,"tree":[],"storefront":"/r/TheresAFewConors","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/TheresAFewConors/MSSprinkler/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}