For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon SQL like command line

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Informational

Description

Uncommon SQL query in command line of an executed process.

Attacker's Goals

  • An attacker may use SQL queries to steal information stored at the target databases.

Investigative actions

  • Check if the CGO (Causality Group Owner) is known for running SQL queries in the organization.

Variations

Uncommon SQL like command line executed by a remote actor

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Medium

Description

Uncommon SQL query in command line of a process which executed remotely.

Attacker's Goals

  • An attacker may use SQL queries to steal information stored at the target databases.

Investigative actions

  • Check if the CGO (Causality Group Owner) is known for running SQL queries in the organization.

Uncommon SQL like command line executed by an RMM tool

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Medium

Description

Uncommon SQL query in command line of a process executed by a Remote Monitoring & Management tool.

Attacker's Goals

  • An attacker may use SQL queries to steal information stored at the target databases.

Investigative actions

  • Check if the CGO (Causality Group Owner) is known for running SQL queries in the organization.

Uncommon SQL like command line executed by an uncommon CGO

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Low

Description

Uncommon SQL query in command line of an executed process.

Attacker's Goals

  • An attacker may use SQL queries to steal information stored at the target databases.

Investigative actions

  • Check if the CGO (Causality Group Owner) is known for running SQL queries in the organization.

Was this helpful?