Metasploit provides a lot of tools for enumerating and exploiting MS SQL.
auxiliary/scanner/mssql/mssql_ping
— Discover MS SQL servers (alternatively, use --script=ms-sql-info
with Nmap)
auxiliary/scanner/mssql/mssql_login
— Brute force logins
auxiliary/admin/mssql/mssql_enum
— Enumerate databases
exploit/windows/mssql/mssql_payload
— Get a shell