MSSprinkler: A Non-Disruptive Password Spraying Tool for M365
MSSprinkler
MSSprinkler is a password-spraying utility for organizations to test their M365 accounts from an external perspective. It employs a ‘low-and-slow’ approach to avoid locking out accounts and provides verbose information related to accounts and tenant information.
Feature
- Automatically spray a list of M365 accounts with a password list.
- Low-and-slow approach to avoid locking out accounts.
- Smart detect accounts that do not exist or are locked out, skipping over these to reduce unnecessary traffic and speed up testing.
- Ability to override the default threshold to better match the organizations policy, if required.
- Verbose output, revealing additional information about accounts:
- Detect if an account is locked out.
- Detect if a user exists in the tenant or not.
- Detect if MFA is in use for a given user without triggering the MFA push.
- Output and store results into a csv file.