SQL Injection - Common SQLi Payloads in HTTP URI Query String
Detects common SQL injection patterns within the HTTP URI query string. The rule monitors established network traffic to web servers and uses regex matching to identify attempts to use SQL keywords like UNION SELECT, OR 1=1 boolean-based attacks, blind SQL injection techniques (sleep/benchmark), and attempts to access information_schema metadata tables.
Suricata

