NetExec MSSQL Query

Run an arbitrary SQL query against MSSQL via NetExec. Faster than firing up impacket-mssqlclient when you only need one statement (e.g. SELECT @@version, SELECT name FROM sys.databases).

Tool
nxc
Category
Enumeration / MSSQL
Platform
linux
Requires
password
Protocols
MSSQL

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc mssql <target> -u '<user>' -p '<password>' -q '<sql-query>'

Credential variants

The same attack using a different authentication material.

Local SQL Auth requires password

nxc mssql <target> -u 'sa' -p '<password>' --local-auth -q '<sql-query>'

Windows Auth requires password

nxc mssql <target> -u '<user>' -p '<password>' --windows-auth -q '<sql-query>'

Hash Auth requires NTLM hash

nxc mssql <target> -u '<user>' -H <nt-hash> -q '<sql-query>'

Examples

nxc mssql 10.10.10.10 -u sa -p 'Password123!' --local-auth -q 'SELECT @@version'

Tags

netexec nxc mssql query