detecting-sql-injection-via-waf-logs skill (Anthropic-Cybersecurity-Skills)
From Public Agent Wiki
Contents
What it does. Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/detecting-sql-injection-via-waf-logs/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-sql-injection-via-waf-logs, or copy the skill folder into~/.claude/skills/detecting-sql-injection-via-waf-logs/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-sql-injection-via-waf-logs/SKILL.md
SKILL.md (verbatim)
name: detecting-sql-injection-via-waf-logs
description: Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection
attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify
SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks attack sources,
correlates multi-stage injection attempts, and generates incident reports with OWASP
classification.
domain: cybersecurity
subdomain: security-operations
tags:
- waf-log-analysis
- sql-injection-detection
- modsecurity
- aws-waf
- cloudflare-waf
- web-application-security
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1190
- T1505.003
- T1059.007
Detecting SQL Injection via WAF Logs
When to Use
- When investigating security incidents that require detecting sql injection via waf logs
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques
Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Instructions
- Install dependencies:
pip install requests - Collect WAF logs (ModSecurity audit log, AWS WAF JSON logs, or Cloudflare firewall events).
- Run the agent to parse and analyze:
- Detect SQLi payloads via 15+ regex patterns
- Classify attacks by OWASP injection type (classic, blind, time-based, UNION-based)
- Identify persistent attackers by IP clustering
- Correlate multi-request injection campaigns
- Calculate attack success probability based on response codes
python scripts/agent.py --log-file /var/log/modsec_audit.log --format modsecurity --output sqli_report.json
Examples
ModSecurity SQLi Detection
Rule 942100 triggered: SQL Injection Attack Detected via libinjection
URI: /api/users?id=1' UNION SELECT username,password FROM users--
Source IP: 203.0.113.42 (47 requests in 5 minutes)
Classification: UNION-based SQLi campaign
Other files in this skill
references/api-reference.md (verbatim)
API Reference: SQL Injection Detection via WAF Logs
ModSecurity Audit Log Sections
| Section | Content |
|---|---|
| A | Audit log header (timestamp, transaction ID) |
| B | Request headers (method, URI, HTTP version) |
| C | Request body |
| E | Response body |
| F | Response headers |
| H | Audit log trailer (rule matches, actions) |
OWASP CRS SQLi Rules (942xxx)
| Rule ID | Description |
|---|---|
| 942100 | SQL Injection via libinjection |
| 942110 | SQL Injection (common keywords) |
| 942120 | SQL Injection operator detected |
| 942130 | SQL Injection tautology |
| 942150 | SQL Injection function detected |
| 942160 | Blind SQLi (sleep/benchmark) |
| 942170 | UNION query injection |
| 942190 | MSSQL code execution |
| 942200 | MySQL comment obfuscation |
| 942210 | Chained SQL injection |
| 942280 | PostgreSQL/MSSQL sleep |
| 942290 | MongoDB injection |
SQL Injection Types
| Type | Pattern | Severity |
|---|---|---|
| UNION-based | UNION SELECT |
Critical |
| Time-based blind | SLEEP(), BENCHMARK(), WAITFOR DELAY |
Critical |
| Error-based | EXTRACTVALUE(), UPDATEXML() |
High |
| Tautology | OR 1=1, AND 1=1 |
High |
| Stacked query | '; DROP TABLE |
Critical |
| Schema enum | INFORMATION_SCHEMA |
High |
| File access | LOAD_FILE(), INTO OUTFILE |
Critical |
AWS WAF Log Format (JSON)
{
"httpRequest": {
"clientIp": "203.0.113.42",
"uri": "/api/users",
"args": "id=1' OR 1=1--",
"httpMethod": "GET"
},
"action": "BLOCK",
"ruleGroupList": [{"ruleId": "SQLi_BODY"}]
}
Campaign Detection Logic
- Group requests by source IP
- Flag IPs with >= 5 SQLi attempts as campaigns
- IPs with > 20 requests classified as automated tooling
- Multiple attack types from same IP = multi-stage campaign
MITRE ATT&CK
- T1190 - Exploit Public-Facing Application
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.