Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
Flags HTTP GET URIs containing SQL injection indicator strings in webserver access logs, excluding 404 responses.
- Category
- webserver
- Author
- Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank) (SigmaHQ), DRL 1.1
- Published
- 2020-02-22
- Updated
- 2026-07-31
ATT&CK techniques
Initial AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags HTTP GET requests where the requested URI contains common SQL injection string patterns and encoded payloads (e.g., UNION SELECT, OR 1=1, SELECT version/database, and time-delay function usage). Attackers use these payloads to probe for database query weaknesses and potentially extract or manipulate data. It relies on webserver access log fields for request method, URI content, and HTTP status, including the exclusion of a specific 404 status filter set.
Reporting behind it
- acunetix.comhttps://www.acunetix.com/blog/articles/exploiting-sql-injection-example/
- acunetix.comhttps://www.acunetix.com/blog/articles/using-logs-to-investigate-a-web-application-attack/
- brightsec.comhttps://brightsec.com/blog/sql-injection-payloads/
- github.comhttps://github.com/payloadbox/sql-injection-payload-list
- book.hacktricks.xyzhttps://book.hacktricks.xyz/pentesting-web/sql-injection/mysql-injection
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/web/webserver_generic/web_sql_injection_in_access_logs.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
id: 60532039-8cb3-4661-b3fd-ee5543346a84
status: test
description: This rule flags HTTP GET requests where the requested URI contains common SQL injection string patterns and encoded payloads (e.g., UNION SELECT, OR 1=1, SELECT version/database, and time-delay function usage). Attackers use these payloads to probe for database query weaknesses and potentially extract or manipulate data. It relies on webserver access log fields for request method, URI content, and HTTP status, including the exclusion of a specific 404 status filter set.
references:
- https://www.acunetix.com/blog/articles/exploiting-sql-injection-example/
- https://www.acunetix.com/blog/articles/using-logs-to-investigate-a-web-application-attack/
- https://brightsec.com/blog/sql-injection-payloads/
- https://github.com/payloadbox/sql-injection-payload-list
- https://book.hacktricks.xyz/pentesting-web/sql-injection/mysql-injection
- https://github.com/SigmaHQ/sigma/blob/master/rules/web/webserver_generic/web_sql_injection_in_access_logs.yml
author: Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank), Huntrule Team
date: 2020-02-22
modified: 2023-09-04
tags:
- attack.initial-access
- attack.t1190
logsource:
category: webserver
detection:
selection:
cs-method: GET
keywords:
- "@@version"
- "%271%27%3D%271"
- "=select "
- =select(
- =select%20
- concat_ws(
- CONCAT(0x
- from mysql.innodb_table_stats
- from%20mysql.innodb_table_stats
- group_concat(
- information_schema.tables
- json_arrayagg(
- or 1=1#
- or%201=1#
- "order by "
- order%20by%20
- "select * "
- select database()
- select version()
- select%20*%20
- select%20database()
- select%20version()
- select%28sleep%2810%29
- SELECTCHAR(
- table_schema
- UNION ALL SELECT
- UNION SELECT
- UNION%20ALL%20SELECT
- UNION%20SELECT
- "'1'='1"
filter_main_status:
sc-status: 404
condition: selection and keywords and not 1 of filter_main_*
falsepositives:
- Java scripts and CSS Files
- User searches in search boxes of the respective website
- Internal vulnerability scanners can cause some serious FPs when used, if you experience a lot of FPs due to this think of adding more filters such as "User Agent" strings and more response codes
level: high
license: DRL-1.1
related:
- id: 5513deaf-f49a-46c2-a6c8-3f111b5cb453
type: derived