Hunting for M365 Password Spraying | Huntress
ID: c2ccfa7f-a833-5ff4-9f97-e8e767a40aac
STIX ID: report--c2ccfa7f-a833-5ff4-9f97-e8e767a40aac
Feed Name: Huntress Blog
Threat Score
This Huntress write-up analyzes password-spraying activity observed against Microsoft 365, describing attacker tradecraft (jitter/delays, use of cloud services to rotate IPs), example tools (TREVORspray, CredMaster, git-rotate), hunting queries and telemetry signals to detect credential theft, and recommended mitigations including blocking legacy authentication, implementing strong/ phishing-resistant MFA, and Entra password protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
