Files
splunk-security_content/docs/_stories/sql_injection.md
T
2021-09-20 21:23:13 -04:00

1.5 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
SQL Injection 2017-09-19 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Web

Description

Use the searches in this Analytic Story to help you detect structured query language (SQL) injection attempts characterized by long URLs that contain malicious parameters.

  • ID: 4f6632f5-449c-4686-80df-57625f59bab3
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Web
  • Last Updated: 2017-09-19
  • Author: Bhavin Patel, Splunk

Narrative

It is very common for attackers to inject SQL parameters into vulnerable web applications, which then interpret the malicious SQL statements.
This Analytic Story contains a search designed to identify attempts by attackers to leverage this technique to compromise a host and gain a foothold in the target environment.

Detections

Name Technique Type
SQL Injection with Long URLs None TTP

Reference

source | version: 1