Password Spraying Explained: Policies, Lockouts, and badPwdCount

Introduction After writing some articles about (what are considered to be) “boring” topics, such as SMB / LDAP signing, email security, and firewalls, I thought I’d dive into something a bit more exciting. Password spraying is a topic I had wanted to explore for quite some time. I had also starred tools such as conpass, but never found the opportunity to explore the underlying concepts in more detail. Until now. In this article, I won’t try to replicate hackndo’s post, although there will be some duplicated information for context purposes, but rather act as a complement to it. As such, some concepts, like GPO and PSO ordering, won’t be explained but links for further reading will be provided instead. ...

August 8, 2026 · mollysec

Password Audits Part 4: Analysing Results

Introduction We extracted the NTDS, organised it, and finally recovered as many hashes as our timeframe and available resources allowed. We have now reached the final part of the process! Now, it is time to produce some value from analysing our final dataset! Extract NTDS → Clean/Organise NTDS → Crack Hashes → Analyse Results At this point, we have a collection of recovered credentials (the Hashcat .potfile) and a rough understanding of how successful our password-cracking process was. However, simply knowing that a certain percentage of hashes were recovered does not say much. ...

July 25, 2026 · mollysec