Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sqlwinds — SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit | Kitploit
Tools/GitHubGitHub/blue0x1/sqlwinds
Privilege EscalationPersistence MechanismsExploitationLateral MovementConfiguration AuditingData ExfiltrationPost-ExploitationPenetration TestingRed TeamingDatabase Security
GitHub
141 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
blue0x1/sqlwinds

sqlwinds

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

View Repository

SQLWinds

SQL Security Assessment & Post-Exploitation Toolkit

SQLWinds is a command-line tool for security testing and exploiting Microsoft SQL Server. It provides an interactive environment to deeply analyze servers, escalate privileges, execute attacks, and pivot through networks all with specialized commands for tasks like in-memory code execution and SCCM database exploration.


SQLWinds


📖 Documentation & Resources

Wiki Issues Releases

Quick Links:

  • Full Documentation & Wiki - Complete usage guide and command reference
  • Report an Issue - Found a bug or have a feature request?
  • Latest Release - Download the newest version

Features

  • Diverse Authentication: Supports SQL, Windows Integrated (--integrated), and Kerberos delegation (--kerberos with --user/--pass).
  • Comprehensive Enumeration:
    • Server info, databases, tables, columns, users, and permissions.
    • Security configuration audit (xp_cmdshell, CLR, OLE, etc.).
    • Sensitive data discovery and secret extraction.
    • Linked server enumeration and exploitation.
  • Post-Exploitation & Lateral Movement:
    • Code Execution: Enable and use xp_cmdshell, OLE Automation Procedures (sp_oacreate), and CLR integration.
    • In-Memory CLR: Load and execute .NET assemblies directly from memory without dropping files to disk (:memclr).
    • Credential Theft: Force SMB authentication to a UNC path for relay attacks (:unc_smb).
    • Registry Interaction: Read registry keys and values via xp_regread.
    • Persistence: Create, list, and execute SQL Agent Jobs.
    • Data Exfiltration: Upload/download files and export query results to CSV/JSON.
  • SCCM Database Interaction: (If the target database is SCCM)
    • Detect SCCM and report version/site info.
    • Inventory hardware, software, collections, and deployments.
    • Perform SCCM-specific security audits.
  • Kerberos Analysis: Check Active Directory for SPNs associated with the target to troubleshoot Kerberos authentication.
  • Instance Discovery: Enumerate SQL Server instances available on the domain.
  • Advanced REPL: Interactive environment with auto-completion and command history.

Installation & Compilation

Quick Build

The repository includes a build.bat script for easy compilation on Windows:

.\build.bat

The compiled SQLWinds.exe executable will be placed in the bin\Release\ directory.

Manual Build

  1. Ensure you have the .NET Framework (≥ 4.6.1) or .NET SDK installed.
  2. Clone the repository:
    git clone https://github.com/blue0x1/sqlwinds.git
    cd sqlwinds
    
  3. Compile the solution:
    msbuild SQLWinds.sln /p:Configuration=Release
    

Usage

Basic Connection

# SQL Authentication
SQLWinds.exe --server TARGET\\INSTANCE --user sa --pass Password123

# Windows Authentication (Current User Context)
SQLWinds.exe --server sql01.corp.local --integrated

# Kerberos Delegation (with provided credentials)
SQLWinds.exe --server sql01.prod.corp.local --kerberos --user CORP\\svc_sql --pass SvcPass123!

# Connect and run a single command
SQLWinds.exe --server 10.0.0.5 --user sa --pass pass --run-cmd "SELECT name FROM sys.databases"

Common Command-Line Options

OptionDescription
--serverTarget server (IP, hostname, instance). Required.
--user, --passCredentials for SQL or Windows auth.
--integratedUse current Windows token for authentication.
--kerberosUse Kerberos authentication flow.
--spn-checkCheck AD for SPNs for the target host.
--run-cmd "<SQL>"Execute a single SQL command and exit.
--run-file file.sqlExecute a SQL script from a file and exit.
--infoGather and display extensive server information.
--getinstanceDiscover SQL instances in the domain and exit.
--list-dbsList databases and exit.
--security-auditPerform security audit and exit.

Interactive REPL Mode

sqlwinds> :info
sqlwinds> :dbs
sqlwinds> :users
sqlwinds> :enable_xp_cmdshell
sqlwinds> :xp whoami
sqlwinds> :spn
sqlwinds> help

Complete REPL Command Reference

Download Tool