IP Library › Granted Patent US 12,732,530
Granted Patent B2
US 12,732,530 · App. 18/971,270 · Granted Sep 8, 2026

Autonomous password spraying during autonomous pentesting

Inventors: Zachary Daniel Hanley (Apex, NC); James Horseman (Wesley Chapel, FL); Anthony Pillitiere (Wesley Chapel, FL)
Assignee: Horizon 3 AI, Inc.
H04L63/1433G06F40/284
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,530
App. No.
18/971,270
Filed
Dec 6, 2024
Granted
Sep 8, 2026
Kind
B2
Examiner
KING, JOHN B
Art Unit
2498
USPC
726/25
Abstract

An autonomous pentesting agent may execute an autonomous pentest of a network involving a password spraying operation and using a custom sequence of password candidates. The autonomous pentesting agent may execute an autonomous pentest of the network associated with multiple user accounts having access to respective network assets. The autonomous pentesting agent may obtain the custom sequence of password candidates for the user accounts based on character pattern tokens and environmental factors of the network. Each character pattern token may be associated with a set of character strings having a defined statistical probability of inclusion in a password that includes the character pattern token. The autonomous pentesting agent may perform the password spraying operation during the autonomous pentest. The password spraying operation may involve successive attempts to compromise a password of user accounts in accordance with the custom sequence of password candidates.

Claims (36)

1 . A method for autonomous password spraying, comprising:

executing an autonomous penetration test of a network associated with a plurality of user accounts and a plurality of network assets, wherein each user account of the plurality of user accounts has access to one or more respective network assets of the plurality of network assets;

obtaining, in association with the autonomous penetration test, a custom sequence of password candidates for the plurality of user accounts based at least in part on one or more character pattern tokens associated with one or more environmental factors of the network, each character pattern token associated with a set of one or more defined character strings having a defined statistical probability of inclusion in a password that includes the character pattern token, wherein the custom sequence of password candidates is ordered according to a total statistical probability of password compromise success; and

performing, during the autonomous penetration test, a password spraying operation associated with unauthorized access to one or more user accounts of the plurality of user accounts, wherein the password spraying operation includes one or more successive attempts to compromise the password of the one or more user accounts in accordance with the custom sequence of password candidates.

2 . The method of claim 1 , further comprising:

parsing respective training passwords of a plurality of training passwords into respective character pattern tokens based at least in part on the one or more environmental factors of the network and lengths of the respective training passwords.

3 . The method of claim 2 , wherein the one or more defined character strings associated with each character pattern token include one or more of: a lowercase character string, an uppercase character string, a number character string, a special character string, or any combination thereof, and wherein each of the one or more defined character strings is associated with a defined length.

4 . The method of claim 2 , wherein the custom sequence of password candidates includes a plurality of password candidates, each password candidate of the plurality of password candidates having a respective combination of character types and lengths that corresponds to the respective combination of the one or more character pattern tokens.

5 . The method of claim 2 , wherein the respective character pattern tokens anonymize the plurality of training passwords such that plain text of the plurality of training passwords is omitted from the one or more character pattern tokens.

6 . The method of claim 1 , further comprising:

tagging one or more training passwords of a plurality of training passwords based at least in part on identifying leet speak, common root words, environmental words, or any combination thereof in the one or more training passwords, wherein a respective tag for the one or more training passwords corresponds to an identified term and the defined statistical probability of the set of one or more defined character strings is further based at least in part on the tagging.

7 . The method of claim 1 , wherein the custom sequence of password candidates is based at least in part on a plurality of training passwords obtained via one or more autonomous penetration tests executed prior to the autonomous penetration test, via a publicly available list of compromised passwords, via one or more user inputs prior to executing the autonomous penetration test, or any combination thereof.

8 . The method of claim 7 , wherein one or more passwords obtained via the one or more autonomous penetration tests of a different network are anonymized.

9 . The method of claim 7 , wherein one or more passwords obtained via the one or more user inputs comprise expired passwords of the one or more user accounts of the plurality of user accounts.

10 . The method of claim 1 , wherein performing the password spraying operation comprises:

attempting to compromise respective user accounts of the plurality of user accounts using respective password candidates of the custom sequence of password candidates, the respective password candidates used in an order of a highest probability to a lowest probability.

11 . The method of claim 1 , wherein the total statistical probability of the password compromise success comprises one or more defined statistical probabilities of the set of one or more defined character strings of each of the one or more character pattern tokens, the set of one or more defined character strings each corresponding to a respective password candidate of the custom sequence of password candidates.

12 . The method of claim 1 , wherein the custom sequence of password candidates is updated in real-time during the autonomous penetration test in accordance with the one or more environmental factors, the one or more environmental factors being identified during the autonomous penetration test.

13 . The method of claim 1 , wherein the custom sequence of password candidates is based at least in part on open source intelligence including information about users of the network available externally to the autonomous penetration test.

14 . The method of claim 1 , wherein the one or more environmental factors include a geographic location of one or more network assets of the plurality of network assets.

15 . An apparatus for autonomous password spraying, comprising:

one or more memories storing processor-executable code; and

one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:

execute an autonomous penetration test of a network associated with a plurality of user accounts and a plurality of network assets, wherein each user account of the plurality of user accounts has access to one or more respective network assets of the plurality of network assets;

obtain, in association with the autonomous penetration test, a custom sequence of password candidates for the plurality of user accounts based at least in part on one or more character pattern tokens associated with one or more environmental factors of the network, each character pattern token associated with a set of one or more defined character strings having a defined statistical probability of inclusion in a password that includes the character pattern token, wherein the custom sequence of password candidates is ordered according to a total statistical probability of password compromise success; and

perform, during the autonomous penetration test, a password spraying operation associated with unauthorized access to one or more user accounts of the plurality of user accounts, wherein the password spraying operation includes one or more successive attempts to compromise the password of the one or more user accounts in accordance with the custom sequence of password candidates.

16 . The apparatus of claim 15 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

parse respective training passwords of a plurality of training passwords into respective character pattern tokens based at least in part on the one or more environmental factors of the network and lengths of the respective training passwords.

17 . The apparatus of claim 16 , wherein the one or more defined character strings associated with each character pattern token include a lowercase character string, an uppercase character string, a number character string, a special character string, or any combination thereof, and wherein each of the one or more defined character strings is associated with a defined length.

18 . A non-transitory computer-readable medium storing code for autonomous password spraying, the code comprising instructions executable by one or more processors to:

execute an autonomous penetration test of a network associated with a plurality of user accounts and a plurality of network assets, wherein each user account of the plurality of user accounts has access to one or more respective network assets of the plurality of network assets;

obtain, in association with the autonomous penetration test, a custom sequence of password candidates for the plurality of user accounts based at least in part on one or more character pattern tokens associated with one or more environmental factors of the network, each character pattern token associated with a set of one or more defined character strings having a defined statistical probability of inclusion in a password that includes the character pattern token, wherein the custom sequence of password candidates is ordered according to a total statistical probability of password compromise success; and

perform, during the autonomous penetration test, a password spraying operation associated with unauthorized access to one or more user accounts of the plurality of user accounts, wherein the password spraying operation includes one or more successive attempts to compromise the password of the one or more user accounts in accordance with the custom sequence of password candidates.

19 . The non-transitory computer-readable medium of claim 18 , wherein the instructions are further executable by the one or more processors to:

tag one or more training passwords of a plurality of training passwords based at least in part on identifying leet speak, common root words, environmental words, or any combination thereof in the one or more training passwords, wherein a respective tag for the one or more training passwords corresponds to an identified term and the defined statistical probability of the set of one or more defined character strings is further based at least in part on the tagging.

20 . The non-transitory computer-readable medium of claim 18 , wherein the custom sequence of password candidates is based at least in part on a plurality of training passwords obtained via one or more autonomous penetration tests executed prior to the autonomous penetration test, via a publicly available list of compromised passwords, via one or more user inputs prior to executing the autonomous penetration test, or any combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: HANLEY, ZACHARY DANIEL; HORSEMAN, JAMES; PILLITIERE, ANTHONY
To: HORIZON 3 AI, INC.
Reel/Frame 069522/0197 →
Continuity (1)
Related Publication 20260163903A1 · Jun 11, 2026
References Cited (19)
US 9888016B1 · Amin · 2018 [cited by examiner]
US 11258819B1 · Agarwal · 2022 [cited by examiner]
US 11329999B1 · Gibbons · 2022 [cited by examiner]
US 11444962B2 · Crume · 2022 [cited by examiner]
US 11973791B1 · Li · 2024 [cited by examiner]
US 12432197B2 · Endler · 2025 [cited by examiner]
US 20080060078A1 · Lord · 2008 [cited by examiner]
US 20150254453A1 · Sugiyama · 2015 [cited by examiner]
US 20150381646A1 · Lin · 2015 [cited by examiner]
US 20160156657A1 · Kaplan · 2016 [cited by examiner]
US 20210288981A1 · Numainville · 2021 [cited by examiner]
US 20220182397A1 · Romero Zambrano · 2022 [cited by examiner]
US 20230015603A1 · Smith · 2023 [cited by examiner]
US 20230019448A1 · Deshmukh · 2023 [cited by examiner]
US 20230134546A1 · Gopalakrishnan · 2023 [cited by examiner]
US 20250260707A1 · Belgi · 2025 [cited by examiner]
JP 3765973B2 · 2006 [cited by examiner]
KR 102710773B1 · 2024 [cited by examiner]
WO WO2024188477A1 · 2024 [cited by examiner]