NetExec MSSQL enum_logins
List every SQL Server login (built-in sa, Windows-mapped accounts, contained DB users) on the instance. Pair with mssql_priv to spot effective sysadmin paths.
- Tool
- nxc
- Category
- Enumeration / MSSQL
- Platform
- linux
- Requires
- password
- Protocols
- MSSQL
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc mssql <target> -u '<user>' -p '<password>' -M enum_logins
Examples
nxc mssql 10.10.10.10 -u sa -p 'Password123!' --local-auth -M enum_logins
Tags
Related commands
- NetExec MSSQL enum_impersonate List every login the current user can EXECUTE AS (IMPERSONATE permission). The classic…
- NetExec MSSQL Query Run an arbitrary SQL query against MSSQL via NetExec. Faster than firing up…