Potential SQL Injection Against Microsoft SQL Server
Identifies potential SQL injection attempts against Microsoft SQL Server by detecting obfuscated T-SQL patterns in SQL Server Audit events. Attackers use CHAR concatenation, CONVERT-based subqueries, and CASE/UNION constructs to bypass input validation and extract data or execute unauthorized statements.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/07/01"
3integration = ["system", "windows"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies potential SQL injection attempts against Microsoft SQL Server by detecting obfuscated T-SQL patterns in SQL
11Server Audit events. Attackers use CHAR concatenation, CONVERT-based subqueries, and CASE/UNION constructs to bypass
12input validation and extract data or execute unauthorized statements.
13"""
14from = "now-9m"
15language = "esql"
16license = "Elastic License v2"
17name = "Potential SQL Injection Against Microsoft SQL Server"
18references = [
19 "https://learn.microsoft.com/en-us/sql/relational-databases/security/auditing/sql-server-audit-action-groups-and-actions",
20 "https://owasp.org/www-community/attacks/SQL_Injection",
21]
22risk_score = 73
23rule_id = "e5d219fd-8362-4b67-a0b8-e3dd4331acdd"
24severity = "high"
25tags = [
26 "Domain: Endpoint",
27 "OS: Windows",
28 "Use Case: Threat Detection",
29 "Tactic: Initial Access",
30 "Data Source: Windows Application Event Logs",
31 "Resources: Investigation Guide",
32 "Noise: Unknown",
33 "Performance: Normal",
34 "Rule Type: ES|QL",
35 "Platform: Windows",
36]
37timestamp_override = "event.ingested"
38type = "esql"
39
40query = '''
41from logs-system.application-*, logs-windows.forwarded*, winlogbeat-* metadata _id, _version, _index
42| where host.os.type == "windows" and winlog.provider_name like "MSSQL*" and event.code == "33205"
43| EVAL message_upper = TO_UPPER(message)
44| where (
45 message_upper RLIKE ".*CONVERT\\(INT,\\(SELECT (CHAR\\(\\d{1,3}\\)\\+){3,}.*" or
46 message_upper RLIKE ".*(CHAR\\(\\d{1,3}\\)\\+){3,}CHAR\\(\\d{1,3}\\).*" or
47 message_upper RLIKE ".*CASE WHEN \\(\\d+=\\d+\\).*UNION SELECT \\d+.*" or
48 message_upper RLIKE ".*WAITFOR DELAY \\'0:0:\\d+\\'.*" or
49 message_upper RLIKE ".*;\\s*(EXEC|EXECUTE)\\s*\\(?\\s*(MASTER\\.)?\\.?XP_CMDSHELL.*" or
50 message_upper RLIKE ".*UNION SELECT (NULL\\s*,\\s*){2,}NULL.*" or
51 message_upper RLIKE ".*'\\w*'\\s*\\+\\s*\\(\\(SELECT @@VERSION\\)\\)\\s*\\+\\s*'\\w*'.*" or
52 message_upper RLIKE ".*(OR|AND)\\s+'?\\d+'?\\s*=\\s*'?\\d+'?\\s*--.*"
53 )
54| eval Esql.original_message = message
55| keep
56 @timestamp,
57 host.id,
58 host.name,
59 host.ip,
60 winlog.computer_name,
61 message,
62 event.outcome,
63 Esql.original_message,
64 _id,
65 _version,
66 _index,
67 data_stream.namespace
68
69| limit 10
70'''
71
72note = """## Triage and analysis
73
74### Investigating Potential SQL Injection Against Microsoft SQL Server
75
76Microsoft SQL Server can write audit records to the Windows Application log as event ID 33205 when SQL Server Audit is
77enabled. Adversaries exploit SQL injection vulnerabilities in applications that query SQL Server, often using obfuscated
78T-SQL such as CHAR concatenation or UNION-based payloads to evade simple signature checks.
79
80#### Possible investigation steps
81
82- Review `Esql.original_message` and `message` for the full audited statement, including the application name, client
83 address, database, and object targeted by the query.
84- Identify the source application or service account associated with the audited session and determine whether it should
85 execute dynamic or user-supplied SQL against the affected database.
86- Correlate with web server, application, or proxy logs around `@timestamp` to identify the HTTP request or client that
87 delivered the malicious input.
88- Check for additional SQL Server Audit events (33205) from the same `host.id` or client address before and after the
89 alert for follow-on statements such as xp_cmdshell, credential access, or data exfiltration.
90- Investigate other alerts on `host.id` during the past 48 hours for signs of post-exploitation or lateral movement.
91
92### False positive analysis
93
94- Security scanners, penetration tests, or authorized application vulnerability assessments may generate matching audit
95 events. Confirm the activity aligns with an approved test window, source address, and application before closing as
96 benign.
97- Custom applications that legitimately build dynamic SQL using CHAR concatenation are uncommon but possible. Review the
98 full statement context and application owner before adding exceptions.
99
100### Response and remediation
101
102- Initiate the incident response process based on the outcome of the triage.
103- If exploitation is confirmed, isolate the affected SQL Server or application tier, block the source IP at the
104 perimeter, and preserve SQL Server Audit and application logs for forensic analysis.
105- Patch or remediate the vulnerable application code path that allowed unsanitized input to reach SQL Server.
106- Review SQL Server permissions for the compromised application account and restrict access to only required databases
107 and objects.
108- Ensure SQL Server is not directly exposed to the internet and that SQL Server Audit remains enabled with appropriate
109 retention.
110"""
111
112setup = """## Setup
113
114SQL Server Audit must be configured to write audit events to the Windows Application log so that event ID 33205 is
115generated by the MSSQLSERVER provider (or MSSQL$<instance> for named instances).
116
117Setup instructions: https://learn.microsoft.com/en-us/sql/relational-databases/security/auditing/create-a-server-audit-and-server-audit-specification
118"""
119
120[rule.investigation_fields]
121field_names = [
122 "@timestamp",
123 "host.id",
124 "host.name",
125 "host.ip",
126 "winlog.computer_name",
127 "message",
128 "event.outcome",
129 "Esql.original_message",
130]
131
132[[rule.threat]]
133framework = "MITRE ATT&CK"
134
135[[rule.threat.technique]]
136id = "T1190"
137name = "Exploit Public-Facing Application"
138reference = "https://attack.mitre.org/techniques/T1190/"
139
140[rule.threat.tactic]
141id = "TA0001"
142name = "Initial Access"
143reference = "https://attack.mitre.org/tactics/TA0001/"
Triage and analysis
Investigating Potential SQL Injection Against Microsoft SQL Server
Microsoft SQL Server can write audit records to the Windows Application log as event ID 33205 when SQL Server Audit is enabled. Adversaries exploit SQL injection vulnerabilities in applications that query SQL Server, often using obfuscated T-SQL such as CHAR concatenation or UNION-based payloads to evade simple signature checks.
Possible investigation steps
- Review
Esql.original_messageandmessagefor the full audited statement, including the application name, client address, database, and object targeted by the query. - Identify the source application or service account associated with the audited session and determine whether it should execute dynamic or user-supplied SQL against the affected database.
- Correlate with web server, application, or proxy logs around
@timestampto identify the HTTP request or client that delivered the malicious input. - Check for additional SQL Server Audit events (33205) from the same
host.idor client address before and after the alert for follow-on statements such as xp_cmdshell, credential access, or data exfiltration. - Investigate other alerts on
host.idduring the past 48 hours for signs of post-exploitation or lateral movement.
False positive analysis
- Security scanners, penetration tests, or authorized application vulnerability assessments may generate matching audit events. Confirm the activity aligns with an approved test window, source address, and application before closing as benign.
- Custom applications that legitimately build dynamic SQL using CHAR concatenation are uncommon but possible. Review the full statement context and application owner before adding exceptions.
Response and remediation
- Initiate the incident response process based on the outcome of the triage.
- If exploitation is confirmed, isolate the affected SQL Server or application tier, block the source IP at the perimeter, and preserve SQL Server Audit and application logs for forensic analysis.
- Patch or remediate the vulnerable application code path that allowed unsanitized input to reach SQL Server.
- Review SQL Server permissions for the compromised application account and restrict access to only required databases and objects.
- Ensure SQL Server is not directly exposed to the internet and that SQL Server Audit remains enabled with appropriate retention.
References
Related rules
- Azure Run Command Correlated with Process Execution
- LLM-Based Wget Activity Triage
- Long Base64 Encoded Command via Scripting Interpreter
- Potential CertiGhost AD CS Machine Identity Mismatch (CVE-2026-54121)
- Potential DNS Exfiltration via Excessive Chunked Queries