NetExec MSSQL enum_logins

List every SQL Server login (built-in sa, Windows-mapped accounts, contained DB users) on the instance. Pair with mssql_priv to spot effective sysadmin paths.

Tool
nxc
Category
Enumeration / MSSQL
Platform
linux
Requires
password
Protocols
MSSQL

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc mssql <target> -u '<user>' -p '<password>' -M enum_logins

Examples

nxc mssql 10.10.10.10 -u sa -p 'Password123!' --local-auth -M enum_logins

Tags

netexec nxc mssql enumeration