quentinhardy/msdat
MSDAT: Microsoft SQL Database Attacking Tool observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3121
- days_rel: n/a
- days_push: 1128
- n_releases_24m: 0
Adoption not part of the score
1016 stars · 145 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
MSDAT is an open-source Python penetration testing tool for remotely testing the security of Microsoft SQL Server databases. It supports credential discovery, privilege escalation, OS command execution via xp_cmdshell/OLE automation, and schema/table dumping.
Use cases
- find valid mssql credentials remotely
- escalate privileges on sql server
- execute os commands through xp_cmdshell
- dump sql server schema and tables
- audit microsoft sql server security
- brute force sql server passwords
- get sql server configuration and user privileges
When to choose
- you are pentesting Microsoft SQL Server 2005-2019 remotely
- you need an all-in-one mssql attack toolkit in Python 3
- you want to test default/weak credentials or escalate a valid sql account
When to avoid
- you target non-Microsoft databases like MySQL or PostgreSQL
- you need a maintained tool with an active release cadence
- you require a licensed or formally supported product
Facets
cli-tool · maturity maintenance
penetration-testing security database vulnerability-scanning security penetration-testing databases python cli windows mssql pentest-tool privilege-escalation password-guessing xp-cmdshell database-attacking linux macos
1 source
- readme: https://github.com/quentinhardy/msdat · fetched 2026-08-28 · 0b76b78a1adb
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| quentinhardy/msdat | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="quentinhardy/msdat")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem