sqlserver-attack

Fail

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides comprehensive instructions for achieving remote command execution using xp_cmdshell and sp_OACreate. It includes specific payloads for reverse shells and downloading malicious binaries via certutil and PowerShell IEX commands.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Instructions are provided to read highly sensitive system files including the Windows SAM hive, web.config files, and hosts files using BULK INSERT and OPENROWSET. Additionally, it details how to extract password hashes from the sys.sql_logins system table.
  • [CREDENTIALS_UNSAFE]: The skill contains a hardcoded list of common weak passwords (e.g., '123456', 'P@ssw0rd') to be used for brute-forcing the sa account.
  • [PRIVILEGE_ESCALATION]: Detailed procedures are included for escalating privileges to sysadmin using sp_addsrvrolemember and exploiting IMPERSONATE permissions to execute commands as higher-privileged users.
  • [PERSISTENCE_MECHANISMS]: The skill describes methods for establishing persistence on the target system by creating scheduled SQL Agent Jobs that execute system commands and creating hidden administrative backdoors.
  • [DYNAMIC_EXECUTION]: The skill details techniques for dynamic code execution and runtime loading, such as creating malicious CLR Assemblies and using OLE Automation Procedures to execute code via wscript.shell.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 12, 2026, 03:49 PM
Security Audit — agent-trust-hub — sqlserver-attack