NetExec MSSQL enum_impersonate
List every login the current user can EXECUTE AS (IMPERSONATE permission). The classic privesc primitive on MSSQL — find a sysadmin you can impersonate, then run mssql_priv to land on xp_cmdshell.
- Tool
- nxc
- Category
- Enumeration / MSSQL
- Platform
- linux
- Requires
- password
- Protocols
- MSSQL
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc mssql <target> -u '<user>' -p '<password>' -M enum_impersonate
Examples
nxc mssql 10.10.10.10 -u lowpriv -p 'Password123!' --local-auth -M enum_impersonate
Tags
Related commands
- NetExec MSSQL enum_logins List every SQL Server login (built-in sa, Windows-mapped accounts, contained DB users)…
- NetExec MSSQL Query Run an arbitrary SQL query against MSSQL via NetExec. Faster than firing up…