O365sprayer
An offensive security tool used to enumerate and spray passwords for O365 accounts on both Managed and Federated AD services.
Install / Use
/learn @securebinary/O365sprayerREADME
Features
- Distinguishes Managed O365 & Federated O365 for the target domain
- Enumerates emails for valid O365 accounts
- Sprays passwords to check for valid credentials
- Provide custom delay between each request
- Provide number of attempts which triggers account lockout
- Provide cool down time for account lockout
- Provide maximum number of account lockouts to tolerate while spraying
Installation
O365 Sprayer was built using go1.18.4. Make sure you use latest version of Go to install successfully. Run the following command to install the latest version:
go install -v github.com/securebinary/o365sprayer@latest
Usage
aidenpearce369@horus~ o365sprayer
____ ___ _
/ __/ ___ ____ __ __ ____ ___ / _ ) (_) ___ ___ _ ____ __ __
_\ \ / -_)/ __// // / / __// -_) / _ | / / / _ \/ _ / / __/ / // /
/___/ \__/ \__/ \_,_/ /_/ \__/ /____/ /_/ /_//_/\_,_/ /_/ \_, /
/___/
O365 Sprayer v1.0.1
-d
Target domain
-u
Email to validate
-p
Password to spray
-U
Path to email list
-P
Path to password list
-enum [DEFAULT : false]
Validate O365 emails
-spray [DEFAULT : false]
Spray passwords on O365 emails
-delay [DEFAULT : 0.25]
Delay between requests
-lockout [DEFAULT : 5]
Number of incorrect attempts for account lockout
-lockoutDelay [DEFAULT : 15]
Lockout cool down time
-max-lockout [DEFAULT : 10]
Maximum number of lockout accounts
This will display help for the CLI tool. Here are all the required arguments it supports.
License
O365 Sprayer is made with 🖤 by the SecureBinary team. Any tweaks / community contribution are welcome.
Related Skills
node-connect
352.9kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
111.5kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
352.9kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
352.9kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
