Skip to content

Hide Navigation Hide TOC

SQL Injection and Code Injection Attack Payload Detection - ATR-2026-00494 (c40d1aff-1dd9-52f5-86dc-0a8bb644534b)

Detects SQL injection payloads and code injection attack strings in user input. Covers classic SQL injection techniques: UNION SELECT exfiltration, blind boolean-based injection via SLEEP/WAITFOR, INSERT/DROP table manipulation, tautology-based auth bypass (OR 1=1), version/configuration fingerprinting (@@version), shutdown commands, and Python lambda reverse shell patterns. Generalised from garak 'exploitation' probe corpus cluster 'mixed_unassigned' - vendor-specific strings (garak/pwnd) replaced with generic SQL injection keyword patterns to improve real-world coverage.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Plugin Compromise (adbb0dd5-ff66-4b2f-869f-bfb3fdb45fc8) MITRE ATLAS Attack Pattern SQL Injection and Code Injection Attack Payload Detection - ATR-2026-00494 (c40d1aff-1dd9-52f5-86dc-0a8bb644534b) Agent Threat Rules 1