
They do this by dumping net user space/domain to dump all of the users off of the domain. Then they automatically spray every single one of those users. And the vast majority of organizations do not have the ability to successfully detect these types of attacks, which is ridiculous. Uh any SIM with their shot their salt should be able to detect this, but unfortunately it's a little bit rare.