// the find
Tw1sm/SQL-BOF
Library of BOFs to interact with SQL servers
SQL-BOF is a library of Beacon Object Files for interacting with SQL Server during red team engagements, with loaders for Cobalt Strike, Havoc, Adaptix, and Outflank C2. It's a C port of SQLRecon's functionality into the BOF format, built on TrustedSec's CS-Situational-Awareness-BOF template, aimed at pentesters who need SQL Server enumeration and lateral-movement primitives without dropping a full .NET binary on disk.
Multi-C2 support is unusual for a BOF collection — most ship only a Cobalt Strike .cna, this one also has Havoc, Adaptix, and Outflank S1 loaders, so it's not locked to a single framework. It covers the full linked-server attack chain in one place (enumerate links, check/toggle RPC, impersonate, pivot via ADSI or agent jobs) that's normally assembled by hand across several separate SQLRecon calls. Execution primitives are diversified across xp_cmdshell, OLE automation, CLR assembly loading, and agent jobs rather than relying on one technique, which matters since xp_cmdshell alone is the first thing defenders disable or alert on.
There's no documentation beyond the command table in the README — no explanation of how impersonation chaining or CLR loading actually works, so verifying what a module does before running it against a client network means reading entry.c by hand for each one. Prebuilt .x64.o/.x86.o files are checked straight into the repo with no CI building them from src/, so there's no way to confirm a given binary matches its corresponding source without rebuilding yourself. There are no OPSEC notes on detection surface (which commands trip SQL Server audit events like CLR enablement or agent job creation) — SQLRecon's own docs are more thorough on that front than this port is.