Skip to content

Hide Navigation Hide TOC

SQL Injection Information Schema Enumeration - ATR-2026-01604 (cbb0a0f2-8fea-5d8a-906c-49eb2a019205)

Detects SQL injection payloads that query information_schema (or sqlite_master, pg_catalog, sys.tables) to enumerate table names, column names, and data types. Schema enumeration is the reconnaissance phase of SQL injection attacks—it reveals the database layout required to craft targeted UNION SELECT or DML payloads. Targeting agents that expose search/query tools backed by relational databases.

Cluster A Galaxy A Cluster B Galaxy B Level
SQL Injection Information Schema Enumeration - ATR-2026-01604 (cbb0a0f2-8fea-5d8a-906c-49eb2a019205) Agent Threat Rules Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern 1
SQL Injection Information Schema Enumeration - ATR-2026-01604 (cbb0a0f2-8fea-5d8a-906c-49eb2a019205) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1