SQL Injection Classic Payloads in HTTP URI or POST Body

This rule monitors incoming HTTP requests for classic SQL injection patterns, such as UNION SELECT, SLEEP, BENCHMARK, and various SQL commands like DROP or ALTER. These signatures are commonly associated with attempts to gain unauthorized access to database contents, exfiltrate data, or compromise the database integrity via web applications.