Evading Data Access Auditing in Microsoft SQL Server β special commands β and how to close the gaps - Andreas Wolter
Published the final article in my 3-part series about the challenges of auditing access to data in Microsoft #SQLServer, #AzureSQL, and SQL #database in #Fabric: andreas-wolter.com/en/202510_da...
Shedding light on several tricky ways to evade auditing β were you aware of all of themβ
07.10.2025 22:16 β π 1 π 0 π¬ 0 π 0
Bug in Auditing allows for undetected Data Exfiltration by low privileged user - Andreas Wolter
I was asked to review a vulnerability discovered in Auditing Classified Data in #SQLServer. It is a valid security risk, since it enables undetected data exfiltration by a low-privileged user.
For details and guidance, check out my post here: andreas-wolter.com/en/2509-sql-...
09.09.2025 19:01 β π 1 π 0 π¬ 0 π 0
Yea. This was only introduced with SQL Server 2022. Before that DC did not enforce anything
09.09.2025 19:01 β π 0 π 0 π¬ 0 π 0
How to Use Data Classification to Audit specific Data Access in SQL Server - Andreas Wolter
Published a more elegant and straightforward solution for auditing access to specific data in Microsoft #SQLServer and #AzureSQL, using Data Classification: andreas-wolter.com/en/202508_da...
19.08.2025 19:19 β π 2 π 0 π¬ 1 π 0
Important Security fixes for #SQLServer 2016β2022: 5 CVEβs of type Elevation of Privilege Vulnerability. Ranging from #SQLInjection via system procedures to permission adjustments and easy to implement. Secure your systems: msrc.microsoft.com/update-guide...
13.08.2025 22:24 β π 0 π 0 π¬ 0 π 0
Evading Data Access Auditing in Microsoft SQL Server β and how to close the gaps - Andreas Wolter
Evading Data Access Auditing in Microsoft #SQLServer π΅οΈ
this article demonstrates data access that is not captured by common Audit definitions and how to ensure also indirect access to data is audited andreas-wolter.com/en/202508_ev...
07.08.2025 18:32 β π 0 π 0 π¬ 0 π 0
Nice technical insights. - Happy to see my old article being of some use still :) - Thanks for mentioning.
29.07.2025 19:12 β π 0 π 0 π¬ 0 π 0
Recommendation for Security Auditing for databases - with example for Microsoft SQL Server - Andreas Wolter
20
Article: recommended minimum security audit definition for database systems, using Microsoft #SQLServer as example:
Audit every change to the systemβs security configuration. andreas-wolter.com/en/202507_re...
29.07.2025 15:28 β π 1 π 0 π¬ 0 π 0
Managing Database Sprawl: Finding Control in a Growing Environment | LinkedIn
As database environments scale, so do complexity and cost. From forgotten dev instances to sprawling clusters of mission-critical workloads, database sprawl creates risks that are easy to ignoreβand t...
Tomorrow: live Roundtable on a growing issue: database sprawl. It wreaks havoc on performance, security, and cost. Weβll talk openly about how to assess whatβs running and take back control. If this has become a challenge in your organization, I hope youβll join us. www.linkedin.com/events/manag...
17.06.2025 21:11 β π 0 π 0 π¬ 0 π 0
10 hours of SQL Server under attack β takeaways - Andreas Wolter
What happens if you leave #SQLServer exposed to the internet? As you may have seen, that is exactly what I did for my PreCon at the #SQLSaturday New York City conference. Here I am sharing what happened:
10 hours of SQL Server under attack β takeaways
andreas-wolter.com/en/2505_sqls...
13.05.2025 21:47 β π 1 π 0 π¬ 0 π 0
Hacking attempts on SQL Server from Iran
And the winner of the first hacking attempt on the #SQLSaturday NYC Performance Monitoring lab environment is: #Iran π applause applause.. π
I am taking bets for the main event Friday!
07.05.2025 21:30 β π 1 π 0 π¬ 0 π 0
Next Thursday, 4/17, at the NTSSUG user group meeting: how to approach #DataSecurity for #SQLServer and #AzureSQL from a strategic perspective, live at the Microsoft office in Irving, TX. Sign up for the free event here: www.meetup.com/north-texas-...
10.04.2025 16:40 β π 0 π 0 π¬ 1 π 0
31 days left: #SQLServer Performance Monitoring at #SQLSaturday in New York City on May 9th!
Your chance to test your knowledge and analyze my server's workload live during the session! - using Extended Events or DMV queries from your own machine: www.eventbrite.com/e/practical-...
08.04.2025 19:43 β π 0 π 0 π¬ 0 π 0
Performance Monitor
Are you interested in learning how to troubleshoot performance issues on your own, rather than relying on costly consultants like me? π
Join me and others for my PreCon on #SQLServer Performance Monitoring at #SQLSaturday in New York City on May 9th!
Sign-up here: www.eventbrite.com/e/practical-...
03.04.2025 18:15 β π 0 π 0 π¬ 0 π 0
SQL Audit bug
#SQLServer #security admins, attention: #Auditing is missing attempts to change permissions, leading to #repudiation and miss elevation attempts
Please upvote for bug-fix
andreas-wolter.com/en/2502-sql-...
10.02.2025 19:57 β π 0 π 1 π¬ 0 π 0
The challenges for least privilege: When sysadmin is still required in Microsoft SQL Server - Andreas Wolter
The challenges for least privilege: When sysadmin is still required in Microsoft #SQLServer
a fresh update on the sysadmin requirements for SQL Server 2022 - and why CONTROL SERVER can be dangerously misleading. andreas-wolter.com/en/least-pri... #DataSecurity
06.02.2025 18:25 β π 2 π 1 π¬ 0 π 0
Protecting database data at rest: Transparent Data Encryption, Backup Encryption or Always Encrypted - Andreas Wolter
New article out> Protecting database data at rest:
Comparing the different encryption methods SQL Server offers, regarding how well they protect data at rest, and why I don't push for #TDE everywhere.
andreas-wolter.com/en/protectin... #DataEncryption #DatSecurity
16.01.2025 17:11 β π 0 π 1 π¬ 0 π 1
Use TLS 1.2 and trusted certificates to encrypt data in transit for all SQL Servers, including development environments - Andreas Wolter
New article: #TLS 1.2 and trusted certificates to encrypt data in transit for all SQL Servers, including development environments andreas-wolter.com/en/tls-trust... #SQLServer #Encryption
26.11.2024 02:28 β π 0 π 0 π¬ 0 π 0
Principal Program Manager, Microsoft. Azure Stack HCI/Windows Server/Hybrid Cloud. He/Him. Posts are mine and don't represent my company. πΊπΈ π΅π¦
Big Bearded PowerShell Data Automation MVP x2, Blogger, Speaker, Data Saturdays PSConfEU, dbatools, dbachecks, dbatoolsMoL http://beard.media/book
I build AI companies . founder @guardrails_ai #mlops @quakerugby. Past:EVP @datarobot, CEO/founder Algorithmia @mspowerbi @msexcel @CarnegieMellon πΊπΈπΊπΎ
Urbanist in Cleveland Park DC. Husband, dad, Nats fan. Reader of tea leaves.
I make databases go faster. I love teaching, travel, laughing, and collecting vintage sports cars. Las Vegas. He/him, pan.
βοΈ / adventure / π€Ώ / nature / π· / animals - loving as much as the π can offer! Planning 2retire off-grid w/my husband & our seven rescue cats (w/ plans 2rescue more animals); learning so much (solar / water catchment ++). Excited!!
CEO of @dcac.com, Microsoft MVP for Azure and Data Platform, VMware vExpert, #Azure, #AWS, #Cloud, #IT #Security
Science Teacher Educator, AI art designer, Video producer, rap artist at The Sharpshootaz. #HeartcoreTheResurrection
Database fire fighter. Started with SQL7 ;-)
Also handling SQL Server flavors in the cloud. πͺοΈ
You can also find me at www.sqlservercentral.com/forums/user/alzdba
Founder & Consultant at @SHAConsultingUK [X], Data Platform MVP, Trainer, Speaker, Community Activist, Freelancer, Adoptive Dad and Coffee Addict.
CEO, Data Platform MVP, PASS Community Leader Germany, Data & AI Focus, Golden Retriever Fan, Vita Assistance Dogs supporter, LR Defender Driver, happy man
Passionate Community guy from Germany. Microsoft Regional Director and Data Platform MVP. Foodie as well.
Tinker, tailor, banker, sailor...
Microsoft Data Platform MVP for 12 years, now Azure SQL PM, with huge passion for Data and Development.
Microsoft Data Platform MVP, #vExpert, Data Professional, and #bacon lover (not in that order). #data #analytics #python #infosec