Search and filter across all detection sources
273 rules
[EXTRAHOP] SQL Injection (SQLi) Attack
[WEB-ATTACKS] Sqlmap SQL Injection Scan
SQL Server library use.
SQL Server filestream information.
sql1433_SQL [yara]
Chinese Hacktool Set - file SQL.exe
sql1433_SQL [malware]
SQLMap [yara]
This signature detects the SQLMap SQL injection tool
SQL Server process ID.
SQLMap [malware]
SQL Server Network Interface library unregistered
SQL Server error.
SQL Server messages.
[WEB-ATTACKS] SQL Power Injector SQL Injection User Agent Detected
SQL Server auditing deactivated
Detects scenarios where an attacker deactivates SQL Server auditing capacities. SQL auditing requires previous configuration on each SQL instance.
HKTL_SqlMap [yara]
Detects sqlmap hacktool
with_sqlite [malware]
Rule to detect the presence of SQLite data in raw image
SQL Server database auditing deactivated
Detects scenarios where an attacker deactivates SQL Server database auditing capacities. SQL auditing requires previous configuration on each SQL instance.
HKTL_SqlMap_backdoor [yara]
Detects SqlMap backdoors
MS-SQL service detected
NGINX - Sql injection patterns
'Detects possible sql injection patterns'
Tomcat - Sql injection patterns
SQLCracker [yara]
Chinese Hacktool Set - file SQLCracker.exe
SQLTools [yara]
Chinese Hacktool Set - file SQLTools.exe
SQLCracker [malware]
SQLTools [malware]