Ross ROSS = Recommend OSS · open-source software intelligence for agents

dafthack/MSOLSpray

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled. observed · 2026-08-28

github.com/dafthack/MSOLSpray · PowerShell · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2361
  • days_rel: n/a
  • days_push: 897
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1100 stars · 186 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

MSOLSpray is a PowerShell-based password spraying tool for Microsoft Online (Azure AD/O365) accounts. It leverages Azure AD OAuth2 error codes to report valid credentials, MFA status, tenant/user existence, and account lockout or disabled states, doubling as a Microsoft Online recon tool.

Use cases

  • spray a single password against a list of O365 user accounts
  • enumerate which Azure AD users exist in a tenant
  • detect whether target accounts have MFA enabled
  • find valid Microsoft Online credentials during authorized penetration tests
  • rotate source IPs with FireProx to avoid Azure Smart Lockout
  • identify locked or disabled accounts during a spray

When to choose

  • you need verbose Azure AD error-code feedback beyond just valid/invalid credentials
  • you want a lightweight PowerShell tool with no dependencies for O365 password spraying
  • you need account enumeration and MFA detection alongside spraying
  • you plan to pair spraying with FireProx for IP rotation

When to avoid

  • you have no explicit authorization to test the target accounts
  • you need multi-password spraying with complex password lists per user
  • you need a cross-platform tool outside Windows PowerShell
  • you want to avoid any risk of account lockouts on production tenants

Facets

cli-tool · maturity stable

security penetration-testing auth cli security penetration-testing cloud-computing windows cli password-spraying azure-ad office365 red-team account-enumeration powershell

1 source

Member repositories

RepositoryRoleHealth v2
dafthack/MSOLSpraymain32

For agents

markdown · JSON · MCP: product_card(name="dafthack/MSOLSpray")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem