One misconfigured flag during a password spray can lock every account in the domain and end your exam attempt before lunch. In timed assessments like OSCP, CRTP, or OSEP, spraying isn’t a brute-force shortcut. It’s a high-stakes enumeration step where precision beats speed. You’re working against a 24-hour clock and a finite number of allowed authentication failures, so treat this as surgical work, not a numbers game. Default Windows domain lockout policies typically trigger after five failed attempts within thirty minutes. Unsprayed brute force in an exam setting is catastrophic.
Password spraying is an enumeration technique, not an exploitation shortcut. Treat it as data gathering that informs lateral movement, not a guaranteed path to admin. That distinction should shape how you approach the keyboard when the pressure peaks.
Why Password Spraying Fails in Exam Environments
Account lockouts happen because candidates skip policy validation and assume the lab mirrors a default configuration. You might have practiced on boxes with no lockout threshold, but exam domains often enforce strict limits, either to simulate real-world defenses or to stop students from accidentally breaking the infrastructure. Send ten passwords at one user instead of one password at ten users, and you’ve violated the core principle of safe spraying and triggered the exact defense you were trying to avoid.
The consequences don’t stop at locked accounts. Defensive logging in modern AD labs often flags rapid authentication spikes even when they stay under the lockout threshold, and some exam environments silently drop traffic from offending IPs without warning. In CRTP and OSEP lab environments, spraying with less than sixty-second intervals between attempts consistently triggers defensive alerts or account locks. Your tool can report success while the backend has already blacklisted your session, and you end up debugging a phantom connection for hours.
Time pressure makes this worse, because fatigue wears down discipline. At hour sixteen, the temptation to raise thread counts or cut delays gets hard to resist, yet that one decision can wipe out hours of prior enumeration. The methodology exists specifically to counter that drift under stress.
Pre-Spray Enumeration and Policy Validation
Don’t send a single authentication request until you’ve queried the domain’s lockout threshold and reset window. Tools like netexec or crackmapexec pull this data silently over SMB or LDAP without burning failure counts, giving you the exact parameters to configure your spray safely. This step takes seconds and heads off the most common cause of exam-day lockouts.
nxc smb 10.10.10.5 -u '' -p '' --pass-pol
The output gives you three values that matter: lockout threshold, lockout duration, and observation window. If the threshold is five and the window is thirty minutes, space attempts so no single account takes more than four failures per half-hour cycle. Using netexec with --no-bruteforce and --continue-on-success flags prevents lockouts while capturing every valid credential pair in a single pass, which is why it’s the baseline for pre-spray reconnaissance.
You also need a validated user list before spraying starts. Enumerate usernames via Kerberos AS-REQ, LDAP queries, or RID cycling, then cross-reference against active sessions or group memberships to prioritize targets. Spraying disabled accounts, service principals, or honeypots wastes time and raises detection risk without yielding usable credentials. A clean target list keeps your failure budget intact for accounts that actually matter.
This validation phase belongs inside your broader structured enumeration workflow, not as an isolated task. Sequencing matters: spray too early and you lack context for interpreting results; spray too late and you’re out of time to exploit anything you recover.
Executing the Password Spraying Methodology Safely
Safe execution means explicit delay configuration and jitter to mimic human behavior and respect policy boundaries. Your command line has to encode the constraints you found during enumeration, not lean on tool defaults built for permissive environments. The syntax below enforces a ninety-second interval between attempts per user, continues after finding valid credentials, and stops before a five-attempt lockout threshold.
nxc smb 10.10.10.0/24 -u users.txt -p 'Winter2026!' --no-bruteforce --continue-on-success --jitter 90
Representative output makes it easy to tell valid credentials from locked or invalid accounts, which matters when you’re scanning results under time pressure:
SMB 10.10.10.12 445 DC01 [+] CORPjsmith:Winter2026! (Pwn3d!)
SMB 10.10.10.15 445 WS03 [-] CORPadmin:Winter2026! STATUS_ACCOUNT_LOCKED_OUT
SMB 10.10.10.18 445 WS07 [-] CORPsvc_backup:Winter2026! STATUS_LOGON_FAILURE
The [+] line confirms access. Document it immediately. STATUS_ACCOUNT_LOCKED_OUT tells you either your delay was too short or another process burned failures before your spray reached this host. STATUS_LOGON_FAILURE is expected for a wrong password and confirms the account is still active. Reading these distinctions in real time stops you from repeating a failed approach or missing a hit buried in verbose output.
Always test your spray configuration against a single known-invalid account first, to check timing and parsing before you point it at the full user list. This dry run catches syntax errors, network timeouts, or an unexpected policy change without burning your failure budget on production targets.
Tool Selection for Active Directory Assessments
Different tools trade off speed, safety, and protocol coverage differently, and picking the wrong one wastes exam hours you don’t have. The table below compares the three most relevant options based on observed behavior in OSCP, CRTP, and OSEP labs.
| Tool | Speed | Safety Features | Protocol Support | Best Exam Use Case |
|---|---|---|---|---|
| netexec | Moderate | Built-in jitter, lockout awareness, continue-on-success | SMB, LDAP, WinRM, MSSQL | OSCP, CRTP, general AD enumeration |
| kerbrute | Fast | Username enumeration only, no native delay logic | Kerberos AS-REQ | Initial user discovery, offline-safe |
| sprayhound | Slow | Smart threshold tracking, BloodHound integration | LDAP, Kerberos | OSEP, complex multi-domain scenarios |
netexec is the most reliable choice for spraying in timed exams because its safety features are on by default and its output slots straight into reporting workflows. kerbrute is excellent for username enumeration but has no built-in delay logic, so it’s dangerous for actual credential testing unless you wrap it in external throttling. sprayhound gives you sharper intelligence for advanced engagements, but the added complexity and slower execution rarely pay off in entry-to-mid-level certifications.
For CRTE or CARTP candidates targeting legacy protocols or non-standard configurations, verify tool compatibility during lab practice before relying on it in the exam. Some older Windows Server versions handle SMB signing or NTLMv2 differently, and a tool that works flawlessly against Server 2019 can fail silently against 2012 R2. Practice with CRTP practice scenarios to validate your toolchain against realistic targets before exam day.
Recognizing Failure Modes and Pivoting
Spraying fails in recognizable ways. Catch the signal early and you save your remaining exam time. Unexpected lockouts across multiple accounts point to either a misread policy or concurrent activity from other students sharing the lab. Silent drops, where the tool hangs indefinitely with no status codes, suggest network-level blocking or a firewall rule tripped by your traffic pattern. Consistent STATUS_LOGON_FAILURE across every user after an initial success or two can mean the password list is exhausted, or the domain rotated credentials mid-exam.
When primary spraying fails, pivot immediately to other credential acquisition vectors. Check for cached credentials in SYSVOL or GPP files, extract hashes from compromised hosts for offline cracking, or review LSA secrets and DPAPI blobs on machines you already own. None of these paths burn authentication attempts, and they often yield higher-value accounts than a generic spray. Abandon spraying entirely if two consecutive cycles produce no new credentials despite correct configuration. Continuing past that point violates sound exam pacing strategy and steals time from higher-probability tasks.
Document every failure mode you hit, with timestamps and error messages. This record does two things: it shows thorough methodology in your report, and it builds a personal knowledge base for next time. Exams test your ability to adapt when a planned approach fails, and structured pivoting scores points even when the initial vector gives you nothing.
Post-Exploitation Validation After a Successful Spray
Validating access without tripping secondary defenses takes restraint and immediate documentation. Don’t spawn shells or run commands the moment you get a [+]. Verify the credential first with a non-destructive protocol check. That confirms validity while staying under endpoint detection systems that watch process creation or PowerShell invocation.
nxc smb 10.10.10.12 -u jsmith -p 'Winter2026!' --shares
Once confirmed, capture screenshots or terminal output showing both the successful authentication and the resulting access level. OffSec and HTB certifications need a clear evidence chain, and a shell going unstable later should never cost you proof of initial compromise. Map the compromised account’s permissions, group memberships, and accessible resources right away. That context decides whether the credential opens up lateral movement or is a dead end. Valid credentials feed directly into Active Directory attack paths that lead to domain escalation, but only if you document the relationships before moving forward.
Don’t modify the target system during validation. Creating files, changing registry keys, or adding scheduled tasks leaves forensic artifacts that can interfere with other students’ exam sessions or break engagement rules. Read-only validation satisfies reporting requirements and keeps lab integrity intact for everyone.
Integrating Spraying Into Your Exam Time Management
Password spraying occupies a specific niche in the 24-hour window and should never eat disproportionate time. Schedule it after initial service enumeration and user listing but before deep manual exploitation of individual hosts. That sequencing gives you enough target data to spray efficiently while leaving time to actually use any credentials you recover. Running sprays in the final four hours of an exam is almost always a mistake; the lockout risk outweighs the reward once there’s no time left to recover.
Box off a fixed window for spraying, typically thirty to forty-five minutes including policy validation and result analysis. If that window runs out without real progress, move on, no matter how close you feel to a breakthrough. Exam scoring rewards breadth of compromise over depth in a single vector, and pouring hours into a stubborn spray keeps you from finding easier wins elsewhere on the network. Track time spent against credentials gained as you go. If the ratio passes twenty minutes per valid credential, the technique isn’t paying off in this environment.
Spraying is one piece of a larger assessment strategy, not the centerpiece. The goal is to show comprehensive offensive capability across multiple domains, not mastery of one technique. Disciplined time allocation is professional judgment, and graders notice candidates who know when to keep pushing and when to redirect effort somewhere more productive.
