name: SQL Injection id: 4f6632f5-449c-4686-80df-57625f59bab3 version: '1.0' date: '2017-09-19' description: Use the searches in this Analytic Story to help you detect structured query language (SQL) injection attempts characterized by long URLs that contain malicious parameters. narrative: 'It is very common for attackers to inject SQL parameters into vulnerable web applications, which then interpret the malicious SQL statements.\ This Analytic Story contains a search designed to identify attempts by attackers to leverage this technique to compromise a host and gain a foothold in the target environment.' author: Bhavin Patel, Splunk type: ESCU references: - https://capec.mitre.org/data/definitions/66.html - https://www.incapsula.com/web-application-security/sql-injection.html tags: analytics_story: SQL Injection usecase: Advanced Threat Detection category: - Adversary Tactics