Files
splunk-security_content/docs/_stories/sql_injection.md
T
2021-10-11 18:18:23 -04:00

1.7 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
SQL Injection 2017-09-19 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Web

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Use the searches in this Analytic Story to help you detect structured query language (SQL) injection attempts characterized by long URLs that contain malicious parameters.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Web
  • Last Updated: 2017-09-19
  • Author: Bhavin Patel, Splunk
  • ID: 4f6632f5-449c-4686-80df-57625f59bab3

Narrative

It is very common for attackers to inject SQL parameters into vulnerable web applications, which then interpret the malicious SQL statements.
This Analytic Story contains a search designed to identify attempts by attackers to leverage this technique to compromise a host and gain a foothold in the target environment.

Detections

Name Technique Type
SQL Injection with Long URLs Exploit Public-Facing Application TTP

Reference

source | version: 1