
Hackers Bruteforce Passwords to Microsoft Online
Source: YouTube · John Hammond · published Oct 20, 2025 · 25:26
Hackers automate credential testing with specialized tools when they obtain stolen username/password data from breaches. This video explores credential checking tools and the evolving cybersecurity landscape around password spraying attacks.
Key Takeaways:
• OpenBullet 2 is a cross-platform automation tool that brute forces credentials by sending requests to target web applications
• Hackers use proxies and IP rotation to mimic legitimate users and avoid detection
• MSOL spray and Entraspray are specialized tools for testing Microsoft/Entra ID accounts
• Team Filtration is a comprehensive framework for attacking Microsoft 365/Entra accounts
• AWS policy changes have affected tools like Fireprox that relied on IP rotation
• Flare's identity exposure management can automatically remediate compromised Entra ID accounts
The cybersecurity cat-and-mouse game continues as attackers develop new methods to test stolen credentials while defenders create better protections.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
How do hackers test the passwords that they've stolen? Like when they have a giant pile of username and password credentials from a recent data breach, how do they see which ones work and which let them into an account that they can compromise? Like there's no way they do this manually trying to log in to each and every one. So hackers automate it. They use scripts or tools or utilities that will loop through every single username and password and brute force or spray different accounts with different passwords and see what lets them in. They check each credential with a cred checker tool. So, in this video, I wanted to talk about and show you some of the credeer tools that exist so we have a better understanding of what's out there, what hackers are using, and how they take advantage of l…