{
  "phase": "L6-mssql-express14-recon",
  "date": "2026-08-17",
  "operator_go": "go (2026-08-17, MSSQL$SQLEXPRESS14 recon on 14.225.11.57)",
  "host": "14.225.11.57 (CTE-SRW-057, geo3.cgis.asia)",
  "access_used": "PostgreSQL superuser superuser_user/postgres -> COPY FROM PROGRAM -> NETWORK SERVICE",
  "access_note": "postgres/Ctech2022!@# on THIS instance is rolsuper=f (rolcreaterole=t). The working RCE role is superuser_user/postgres (rolsuper=t). Corrects L5_windows_host_enum assumption.",
  "mssql_sqlexpress14": {
    "state": "RUNNING, AUTO_START",
    "service_account": "NT Service\\MSSQL$SQLEXPRESS14 (virtual account, NOT SYSTEM)",
    "binary": "MSSQL12.SQLEXPRESS14 => SQL Server 2014 (12.x) Express",
    "second_instance": "SQLEXPRESS (MSSQL12.SQLEXPRESS) also registered",
    "tcp_1433": "LISTENING on 0.0.0.0 (publicly reachable)",
    "client_tools": ["sqlcmd.exe (Client SDK ODBC)", "osql.exe (PTools)", "bcp.exe"],
    "xp_cmdshell_path": "if sysadmin creds obtained -> code exec as NT Service\\MSSQL$SQLEXPRESS14 (SeImpersonate, but NOT SYSTEM)",
    "direct_system": "NO - service is virtual account, not LocalSystem"
  },
  "spooler": {
    "state": "RUNNING, LocalSystem",
    "implication": "PrintSpoofer technically applicable IF we get SeImpersonate context (e.g. via MSSQL xp_cmdshell as NT Service)"
  },
  "kaspersky": {
    "processes": ["avp.exe (AVP.KES.14.0, PID 14032)", "avpsus.exe (avpsus.KES.14.0)", "klnagent.exe (KSC agent)", "avp.exe (PID 17644)", "avpui.exe x2"],
    "klnagent": "PRESENT -> alerts go to central Kaspersky Security Center console. Detection cost is HIGH (centralized incident).",
    "implication": "Any signatured binary (PrintSpoofer/GodPotato) will be quarantined AND reported centrally. Stock potato = burned."
  },
  "network": {
    "public_ip": "14.225.11.57",
    "internal_ips": ["172.30.112.1 (139 listening)", "172.16.2.0/24 (from L5)"],
    "listening": ["135", "139", "445", "1433", "5432 (implied)"]
  },
  "key_findings": [
    "MSSQL Express 2014 is NOT a direct SYSTEM path (virtual service account)",
    "MSSQL gives SeImpersonate context -> enables potato -> but KES 14 + KSC agent makes stock potato loud",
    "sqlcmd.exe present -> can auth to MSSQL locally if creds found",
    "1433 is publicly listening -> external MSSQL auth attempts possible",
    "Spooler RUNNING -> PrintSpoofer viable IF custom/unsigned version used",
    "KSC agent (klnagent) confirmed -> centralized alerting"
  ],
  "next_steps": [
    "Find MSSQL creds (sa or Windows) via GeoServer configs / connection strings / setup logs",
    "If sa creds -> xp_cmdshell as NT Service -> SeImpersonate -> CUSTOM potato (unsigned, renamed, in-memory) -> SYSTEM",
    "Alternative: SQL 2014 Express may have unpatched CVEs (check SP/CU level via reg)",
    "Check GS data_dir actual path (C:\\Program Files\\GeoServer\\data_dir returned empty)",
    "Read MSSQL errorlog for login attempts / existing connections"
  ],
  "confidence": "CONFIRMED (direct sc/reg/tasklist output)",
  "sysmod": "none - read-only sc/reg/tasklist/netstat via COPY FROM PROGRAM",
  "artifacts": "L6_mssql_recon_raw.txt (full output), this file"
}
