Impacket MSSQLClient
Interactive MSSQL shell for command execution and database access
- Tool
- impacket-mssqlclient
- Category
- Lateral Movement / MSSQL
- Platform
- linux
- Requires
- password
- Protocols
- MSSQL
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-mssqlclient '<domain>/<user>:<password>'@<ip>
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-mssqlclient -hashes ':<hash>' '<domain>/<user>'@<ip>
Kerberos Ticket requires Kerberos ticket
impacket-mssqlclient -k -no-pass '<domain>/<user>'@<ip>
Windows Auth requires password
impacket-mssqlclient '<domain>/<user>:<password>'@<ip> -windows-auth
Examples
impacket-mssqlclient 'corp.local/sa:password'@192.168.1.100
impacket-mssqlclient 'corp.local/user:password'@192.168.1.100 -windows-auth
Tags
Related commands
- MSSQLPwner Linked Server Abuse Enumerate and abuse MSSQL linked servers for lateral movement
- NetExec MSSQL Command Exec Execute OS commands through MSSQL — auto-enables xp_cmdshell if disabled and the account…
- NetExec MSSQL Enable CmdShell Enable xp_cmdshell on a MSSQL server for OS command execution
- NetExec MSSQL Linked Servers Enumerate MSSQL linked servers for lateral movement opportunities
- NetExec MSSQL Privilege Check Enumerate and escalate MSSQL server privileges (sysadmin, impersonation, linked servers)
- NetExec MSSQL xp_cmdshell Execute OS commands via MSSQL xp_cmdshell using NetExec