Wordlists

Keep a personal "Wins" list during each engagement.

Password Spraying Tips and Tricks

Examine the password policy

#~ cme smb 10.0.0.250 -u foobar -p 'Fall2020' --pass-pol

Depending on the domain you will likely retrieve the password policy even without having valid user credentials.

ProbablePasswordList V2.0

The Probable Password List is a good place to start. The majority of passwords which are "crackable" will be cracked will be cracked with the wordlists included within.

RockYou2021 | 8.4 Billion Entries

Use this one if either money or time is not a factor. This list will take some cycles, as a comparison the traditional rockyou.txt contains 14.3 million entries making RockYou2021 almost 1000 times bigger.