Potential SQL Injection Against Microsoft SQL Server

Identifies potential SQL injection attempts against Microsoft SQL Server by detecting obfuscated T-SQL patterns in SQL Server Audit events. Attackers use CHAR concatenation, CONVERT-based subqueries, and CASE/UNION constructs to bypass input validation and extract data or execute unauthorized statements.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/07/01"
  3integration = ["system", "windows"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Identifies potential SQL injection attempts against Microsoft SQL Server by detecting obfuscated T-SQL patterns in SQL
 11Server Audit events. Attackers use CHAR concatenation, CONVERT-based subqueries, and CASE/UNION constructs to bypass
 12input validation and extract data or execute unauthorized statements.
 13"""
 14from = "now-9m"
 15language = "esql"
 16license = "Elastic License v2"
 17name = "Potential SQL Injection Against Microsoft SQL Server"
 18references = [
 19    "https://learn.microsoft.com/en-us/sql/relational-databases/security/auditing/sql-server-audit-action-groups-and-actions",
 20    "https://owasp.org/www-community/attacks/SQL_Injection",
 21]
 22risk_score = 73
 23rule_id = "e5d219fd-8362-4b67-a0b8-e3dd4331acdd"
 24severity = "high"
 25tags = [
 26    "Domain: Endpoint",
 27    "OS: Windows",
 28    "Use Case: Threat Detection",
 29    "Tactic: Initial Access",
 30    "Data Source: Windows Application Event Logs",
 31    "Resources: Investigation Guide",
 32    "Noise: Unknown",
 33    "Performance: Normal",
 34    "Rule Type: ES|QL",
 35    "Platform: Windows",
 36]
 37timestamp_override = "event.ingested"
 38type = "esql"
 39
 40query = '''
 41from logs-system.application-*, logs-windows.forwarded*, winlogbeat-* metadata _id, _version, _index
 42| where host.os.type == "windows" and winlog.provider_name like "MSSQL*" and event.code == "33205"
 43| EVAL message_upper = TO_UPPER(message)
 44| where (
 45    message_upper RLIKE ".*CONVERT\\(INT,\\(SELECT (CHAR\\(\\d{1,3}\\)\\+){3,}.*" or 
 46    message_upper RLIKE ".*(CHAR\\(\\d{1,3}\\)\\+){3,}CHAR\\(\\d{1,3}\\).*" or 
 47    message_upper RLIKE ".*CASE WHEN \\(\\d+=\\d+\\).*UNION SELECT \\d+.*" or
 48    message_upper RLIKE ".*WAITFOR DELAY \\'0:0:\\d+\\'.*" or
 49    message_upper RLIKE ".*;\\s*(EXEC|EXECUTE)\\s*\\(?\\s*(MASTER\\.)?\\.?XP_CMDSHELL.*" or
 50    message_upper RLIKE ".*UNION SELECT (NULL\\s*,\\s*){2,}NULL.*" or
 51    message_upper RLIKE ".*'\\w*'\\s*\\+\\s*\\(\\(SELECT @@VERSION\\)\\)\\s*\\+\\s*'\\w*'.*" or
 52    message_upper RLIKE ".*(OR|AND)\\s+'?\\d+'?\\s*=\\s*'?\\d+'?\\s*--.*"
 53  )
 54| eval Esql.original_message = message
 55| keep
 56    @timestamp,
 57    host.id,
 58    host.name,
 59    host.ip,
 60    winlog.computer_name,
 61    message,
 62    event.outcome,
 63    Esql.original_message,
 64    _id,
 65    _version,
 66    _index,
 67    data_stream.namespace
 68    
 69| limit 10
 70'''
 71
 72note = """## Triage and analysis
 73
 74### Investigating Potential SQL Injection Against Microsoft SQL Server
 75
 76Microsoft SQL Server can write audit records to the Windows Application log as event ID 33205 when SQL Server Audit is
 77enabled. Adversaries exploit SQL injection vulnerabilities in applications that query SQL Server, often using obfuscated
 78T-SQL such as CHAR concatenation or UNION-based payloads to evade simple signature checks.
 79
 80#### Possible investigation steps
 81
 82- Review `Esql.original_message` and `message` for the full audited statement, including the application name, client
 83  address, database, and object targeted by the query.
 84- Identify the source application or service account associated with the audited session and determine whether it should
 85  execute dynamic or user-supplied SQL against the affected database.
 86- Correlate with web server, application, or proxy logs around `@timestamp` to identify the HTTP request or client that
 87  delivered the malicious input.
 88- Check for additional SQL Server Audit events (33205) from the same `host.id` or client address before and after the
 89  alert for follow-on statements such as xp_cmdshell, credential access, or data exfiltration.
 90- Investigate other alerts on `host.id` during the past 48 hours for signs of post-exploitation or lateral movement.
 91
 92### False positive analysis
 93
 94- Security scanners, penetration tests, or authorized application vulnerability assessments may generate matching audit
 95  events. Confirm the activity aligns with an approved test window, source address, and application before closing as
 96  benign.
 97- Custom applications that legitimately build dynamic SQL using CHAR concatenation are uncommon but possible. Review the
 98  full statement context and application owner before adding exceptions.
 99
100### Response and remediation
101
102- Initiate the incident response process based on the outcome of the triage.
103- If exploitation is confirmed, isolate the affected SQL Server or application tier, block the source IP at the
104  perimeter, and preserve SQL Server Audit and application logs for forensic analysis.
105- Patch or remediate the vulnerable application code path that allowed unsanitized input to reach SQL Server.
106- Review SQL Server permissions for the compromised application account and restrict access to only required databases
107  and objects.
108- Ensure SQL Server is not directly exposed to the internet and that SQL Server Audit remains enabled with appropriate
109  retention.
110"""
111
112setup = """## Setup
113
114SQL Server Audit must be configured to write audit events to the Windows Application log so that event ID 33205 is
115generated by the MSSQLSERVER provider (or MSSQL$<instance> for named instances).
116
117Setup instructions: https://learn.microsoft.com/en-us/sql/relational-databases/security/auditing/create-a-server-audit-and-server-audit-specification
118"""
119
120[rule.investigation_fields]
121field_names = [
122    "@timestamp",
123    "host.id",
124    "host.name",
125    "host.ip",
126    "winlog.computer_name",
127    "message",
128    "event.outcome",
129    "Esql.original_message",
130]
131
132[[rule.threat]]
133framework = "MITRE ATT&CK"
134
135[[rule.threat.technique]]
136id = "T1190"
137name = "Exploit Public-Facing Application"
138reference = "https://attack.mitre.org/techniques/T1190/"
139
140[rule.threat.tactic]
141id = "TA0001"
142name = "Initial Access"
143reference = "https://attack.mitre.org/tactics/TA0001/"

Triage and analysis

Investigating Potential SQL Injection Against Microsoft SQL Server

Microsoft SQL Server can write audit records to the Windows Application log as event ID 33205 when SQL Server Audit is enabled. Adversaries exploit SQL injection vulnerabilities in applications that query SQL Server, often using obfuscated T-SQL such as CHAR concatenation or UNION-based payloads to evade simple signature checks.

Possible investigation steps

  • Review Esql.original_message and message for the full audited statement, including the application name, client address, database, and object targeted by the query.
  • Identify the source application or service account associated with the audited session and determine whether it should execute dynamic or user-supplied SQL against the affected database.
  • Correlate with web server, application, or proxy logs around @timestamp to identify the HTTP request or client that delivered the malicious input.
  • Check for additional SQL Server Audit events (33205) from the same host.id or client address before and after the alert for follow-on statements such as xp_cmdshell, credential access, or data exfiltration.
  • Investigate other alerts on host.id during the past 48 hours for signs of post-exploitation or lateral movement.

False positive analysis

  • Security scanners, penetration tests, or authorized application vulnerability assessments may generate matching audit events. Confirm the activity aligns with an approved test window, source address, and application before closing as benign.
  • Custom applications that legitimately build dynamic SQL using CHAR concatenation are uncommon but possible. Review the full statement context and application owner before adding exceptions.

Response and remediation

  • Initiate the incident response process based on the outcome of the triage.
  • If exploitation is confirmed, isolate the affected SQL Server or application tier, block the source IP at the perimeter, and preserve SQL Server Audit and application logs for forensic analysis.
  • Patch or remediate the vulnerable application code path that allowed unsanitized input to reach SQL Server.
  • Review SQL Server permissions for the compromised application account and restrict access to only required databases and objects.
  • Ensure SQL Server is not directly exposed to the internet and that SQL Server Audit remains enabled with appropriate retention.

References

Related rules

to-top