Skip to content

Conversation

@n3rada
Copy link

@n3rada n3rada commented Oct 26, 2025

Hello 👋

I want to add this piece of code to enable developers to modify the Workstation ID and Application Name when using the TDS protocol with the MSSQL class.

This allows the security team to leave IoCs or, conversely, enables red activities to be more covert by using things commonly found in the targeted environment.

It's a small PR, but useful!

Best regards,

@anadrianmanrique anadrianmanrique added the enhancement Implemented features can be improved or revised label Nov 7, 2025
Copy link
Collaborator

@gabrielg5 gabrielg5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hey hello, thank you for this PR!

Think it's ok. Added some "OCD" suggestions :D just to leverage the getters you included in the PR.

Checking examples leveraging the MSSQL class, I think would be good add 2 new parameters to the mssqlclient one, to allow users configuring these connection properties (fallback to "" as now, to randomize them)

Thinking long term, to check in future PRs eventually, can be leveraged from ntlmrelayx as well to reuse client properties - in cases they are set -

@gabrielg5 gabrielg5 added the waiting for response Further information is needed from people who opened the issue or pull request label Nov 18, 2025
n3rada and others added 2 commits November 19, 2025 09:22
Co-authored-by: Gabriel Gonzalez <[email protected]>
Co-authored-by: Gabriel Gonzalez <[email protected]>
@n3rada n3rada requested a review from gabrielg5 November 19, 2025 08:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement Implemented features can be improved or revised waiting for response Further information is needed from people who opened the issue or pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants