Overview

You have

Login portal

list of employees/emails

Password strategies to employ

Current / past season with year and !, * etc

City - Local Sport Team

Address

Colleges

Company name

Number and characters as vowels (a β†’ @, e β†’ 3)

Office 365

O365 is linked with everything (VPN, access etc)

https://github.com/blacklanternsecurity/TREVORspray

β†’ O365 spraying tool

delay (base 30s) to avoid being detected

--no-current-ip

e.g.

Untitled

<aside> πŸ“˜ Look for 2022 used tools

</aside>

Don’t want to block everything then ask for lock policy.

Use free VM on AWS etc for --ssh flag, be sure to accept fingerprint before use TREVORspray

<aside> ⚠️ VPN often detect very quickly

</aside>

OWA (outlook web access)

> msfconsole
> search owa
> use auxiliary/scanner/http/owa_login

<aside> πŸ“— Detect valid user delay but don’t detect lock account

</aside>

Other portals

<aside> πŸ“— Burp Suite proxy and intruder

</aside>