Metasploit provides a lot of tools for enumerating and exploiting MS SQL. auxiliary/scanner/mssql/mssql_ping — Discover MS SQL servers (alternatively, use --script=ms-sql-info with Nmap) auxiliary/scanner/mssql/mssql_login — Brute force logins auxiliary/admin/mssql/mssql_enum — Enumerate databases exploit/windows/mssql/mssql_payload — Get a shell