If we have a foothold on domain-joined Windows host, we can useDomainPasswordSpray tool.
If the host is authenticated to the domain, tool will automatically generate a user list from AD, query password policy, and exclude user accounts within one attempt of locking out.
DomainPasswordSpray - Domain Joined
Since the host we are on is domain joined, it will automatically get user list from AD.
So we successfully attempted on password spray using password policy and userlist. Now with several sets of valid credentials in hand, we move to performing credentialed enumeration with various tools such as bloodhound.