Skip to content

Hide Navigation Hide TOC

SQL Injection UNION SELECT Data Exfiltration - ATR-2026-01602 (95ccc395-26cf-5b9f-9a55-f72638d80514)

Detects UNION SELECT injection in agent tool arguments intended to append a second SELECT statement to the original query, exfiltrating data from other tables (e.g., credentials, PII, financial records) alongside the normal result set. This is the primary SQL exfiltration technique targeting AI agents that forward search/filter inputs to SQL queries without parameterization.

Cluster A Galaxy A Cluster B Galaxy B Level
SQL Injection UNION SELECT Data Exfiltration - ATR-2026-01602 (95ccc395-26cf-5b9f-9a55-f72638d80514) Agent Threat Rules Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern 1
SQL Injection UNION SELECT Data Exfiltration - ATR-2026-01602 (95ccc395-26cf-5b9f-9a55-f72638d80514) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1