Password Spraying is an attack that tries a small number of common passwords across many accounts.
It is designed to avoid lockout thresholds and is commonly detected through authentication logs, anomaly monitoring, and identity-protection controls.