MSSQL Server Trust Abuse
Enumeration
Finding Instances From SQL Servers That Have an SPN with the Domain Controller and Discovering Logon Sessions
Get-SQLInstanceDomainFinding Accessible SQL Servers
Get-SQLConnectionTestThreaded
Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded -VerboseRetrieve Basic Server and Information From Target SQL Servers For Each Instance
Get-SQLInstanceDomain | Get-SQLServerInfo -VerboseSearching Database Links
Get-SQLServerLink -Instance <sql_server_domain> -Verbose
# Crawling downfield database links from a SQL Server you can access
Get-SQLServerLinkCrawl -Instance <sql_server_domain> -VerboseNow We Can Execute Commands
Get a Reverse Shell
Last updated