PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server
Tags
attack-pattern: | Data Model Credentials - T1589.001 Powershell - T1059.001 Server - T1583.004 Server - T1584.004 Vulnerabilities - T1588.006 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | b7ce8802-b843-4c1a-8bb1-a9483d682c06 |
Fingerprint | c50a3852ed0723c7 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | July 15, 2016, 7 a.m. |
Added to db | Jan. 18, 2023, 8:38 p.m. |
Last updated | Nov. 18, 2024, 1:38 a.m. |
Headline | PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server |
Title | PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server |
Detected Hints/Tags/Attributes | 34/1/11 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 180 | readme.md |
|
Details | Domain | 1 | sqlserver1.domain.com |
|
Details | Domain | 201 | msdn.microsoft.com |
|
Details | File | 3 | powerupsql.psd |
|
Details | File | 3 | powerupsql.ps1 |
|
Details | File | 1209 | powershell.exe |
|
Details | File | 1 | ms161959.aspx |
|
Details | File | 1 | testdb.mdf |
|
Details | Github username | 11 | netspi |
|
Details | Url | 3 | https://raw.githubusercontent.com/netspi/powerupsql/master/powerupsql.ps1 |
|
Details | Url | 1 | https://msdn.microsoft.com/en-us/library/ms161959.aspx |