1.15.4 SQL Profiler

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Level 1, Scorable
SQL Server Profiler may be used to identify system events that may indicate security risks.
SQL Server Profiler is a user application that captures events that occur on the SQL Server system through the use of defined traces.
There may significant amount of overhead through running SQL Profiler depending on where the application is ran and how many events are
captured. It is a great tool for capturing data over finite periods of time, but is not recommended as a long-term solution for continually
capturing system events.
SQL Server Profiler ships with all versions of SQL Server except SQL Server Express Edition.
ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 100.
Note: Nessus has not performed this query, and this check is only provided for informational purposes.