---
title: "MSP Moment: Squashing an MSSQL Attack"
url: https://daily.dev/posts/msp-moment-squashing-an-mssql-attack-cguy8utx4
source_url: https://www.huntress.com/blog/msp-moment-squashing-an-mssql-attack-acc08886f367
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:39.161Z
updated: 2026-05-31T09:02:51.096Z
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# MSP Moment: Squashing an MSSQL Attack

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 3 min read · 0 upvotes · 0 comments

## Summary

NTConnections, a Washington DC-based MSP, responded to a SQL Server outage that turned into a full incident response. Using Huntress, they discovered attackers had brute-forced the MSSQL SA account, disabled firewall services, downloaded obfuscated backdoors via FTP, installed cryptocurrency miners, deployed antivirus-killing tools, and deleted event logs to cover their tracks. The case study outlines the attack timeline, attacker actions, and how threat hunting and remediation contained the breach before further damage occurred.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/msp-moment-squashing-an-mssql-attack-acc08886f367>

---

[View this post on daily.dev](https://daily.dev/posts/msp-moment-squashing-an-mssql-attack-cguy8utx4)
