Skip to content

Hide Navigation Hide TOC

SQL Injection Destructive DDL Statement - ATR-2026-01601 (028d7a26-85b3-58cc-8989-3acecbb05a08)

Detects SQL injection payloads that attempt destructive DDL operations: DROP TABLE, TRUNCATE TABLE, or unbounded DELETE FROM statements embedded in agent tool arguments. These attacks exploit agents that pass user input directly to database query tools, causing irreversible data destruction. The canonical form uses string-termination ( ' or " followed by ; ) to escape a parameterized context and inject a secondary statement.

Cluster A Galaxy A Cluster B Galaxy B Level
Data Destruction - T1485 (d45a3d09-b3cf-48f4-9f0f-f521ee5cb05c) Attack Pattern SQL Injection Destructive DDL Statement - ATR-2026-01601 (028d7a26-85b3-58cc-8989-3acecbb05a08) Agent Threat Rules 1
Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern SQL Injection Destructive DDL Statement - ATR-2026-01601 (028d7a26-85b3-58cc-8989-3acecbb05a08) Agent Threat Rules 1