1---2name: detecting-sql-injection-via-waf-logs3description: Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks attack sources, correlates multi-stage injection attempts, and generates incident reports with OWASP classification.4license: Apache-2.05---6
7
8# Detecting SQL Injection via WAF Logs
9
10
11## When to Use
12
13- When investigating security incidents that require detecting sql injection via waf logs
14- When building detection rules or threat hunting queries for this domain
15- When SOC analysts need structured procedures for this analysis type
16- When validating security monitoring coverage for related attack techniques
17
18## Detection Gaps & Validation
19
20- **WAF only logs what it inspects:** if SQLi arrives in a JSON body, a header, or a path segment the WAF doesn't parse, no rule (942100/942190/etc.) fires and your log analysis sees nothing. Confirm the WAF parses request bodies and the relevant content types before treating an empty result as "no attack."
21- **Obfuscation evades the signatures you grep for:** inline comments (`UN/**/ION SEL/**/ECT`), case mixing, URL/double-URL encoding (`%2553ELECT`), whitespace alternates (`/**/`, `%0a`, `+`), and `CHAR()`/`CONCAT()` payloads slip literal-regex patterns. Normalize (decode twice, strip comments, collapse whitespace, lowercase) before matching, and lean on libinjection-based rules (942100) rather than only string patterns (942190).
22- **Time-based blind SQLi has no row-count tell:** `SLEEP()`, `BENCHMARK()`, `pg_sleep()`, `WAITFOR DELAY` succeed with normal 200s and no data in the response — detect via response-latency deltas and repeated near-identical requests, not status codes.
23- **Encoding/WAF mode:** Cloudflare/AWS WAF may log the decoded payload while ModSecurity logs raw — parse both forms. Count-only mode (no block) means 200s on malicious requests; don't infer failure from a 200.
24- **Validate the rules fire:** replay an sqlmap run (classic, UNION, and `--technique=T` time-based) through the parser and confirm each OWASP class and the IP-clustering correlation populate. **FP tuning:** apps that legitimately pass SQL keywords (search, reporting) and security scanners cause noise — baseline trusted IPs/endpoints before raising incidents.
25
26## Prerequisites
27
28- Familiarity with security operations concepts and tools
29- Access to a test or lab environment for safe execution
30- Python 3.8+ with required dependencies installed
31- Appropriate authorization for any testing activities
32
33## Instructions
34
351. Install dependencies: `pip install requests`
362. Collect WAF logs (ModSecurity audit log, AWS WAF JSON logs, or Cloudflare firewall events).
373. Run the agent to parse and analyze:
38 - Detect SQLi payloads via 15+ regex patterns
39 - Classify attacks by OWASP injection type (classic, blind, time-based, UNION-based)
40 - Identify persistent attackers by IP clustering
41 - Correlate multi-request injection campaigns
42 - Calculate attack success probability based on response codes
43
44```bash
45python scripts/agent.py --log-file /var/log/modsec_audit.log --format modsecurity --output sqli_report.json
46```
47
48## Examples
49
50### ModSecurity SQLi Detection
51```
52Rule 942100 triggered: SQL Injection Attack Detected via libinjection
53URI: /api/users?id=1' UNION SELECT username,password FROM users--
54Source IP: 203.0.113.42 (47 requests in 5 minutes)
55Classification: UNION-based SQLi campaign
56```