{"id":"T1505.001","name":"SQL Stored Procedures","url":"https://attack.mitre.org/techniques/T1505/001","tactics":["persistence"],"platforms":["Windows","Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0181","stix_id":"x-mitre-detection-strategy--101bde37-6150-45c6-bf88-3a8cda39b2f0","name":"Detection Strategy for SQL Stored Procedures Abuse via T1505.001","url":"https://attack.mitre.org/detectionstrategies/DET0181","analytics":[{"id":"AN0511","stix_id":"x-mitre-analytic--f9fb1a46-02f0-4d89-a3d9-6bed04bd47be","name":"Analytic 0511","description":"Creation or modification of stored procedures invoking xp_cmdshell or CLR assemblies for command execution and persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0181#AN0511","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Application","channel":"Stored procedure creation, modification, or xp_cmdshell invocation via SQL logs or SQL Server auditing","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"CLR Assembly creation, loading, or modification logs via MSSQL CLR integration","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-application"}],"mutable_elements":[{"field":"xp_cmdshell_invocation_threshold","description":"Adjust if legitimate procedures use xp_cmdshell often in environment"},{"field":"CLRAssemblyNameWhitelist","description":"Organization-defined whitelist of legitimate CLR assemblies"},{"field":"TimeWindow","description":"Tune time window to correlate stored procedure creation with process execution"}],"live":true,"detection_strategies":["DET0181"],"techniques":["T1505.001"]},{"id":"AN0512","stix_id":"x-mitre-analytic--2e039fd4-a1f6-4c4b-b47a-56c257335298","name":"Analytic 0512","description":"SQL stored procedures that invoke OS-level commands via `xp_cmdshell` equivalent or via UDF (User-Defined Functions) mechanisms.","url":"https://attack.mitre.org/detectionstrategies/DET0181#AN0512","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"ApplicationLogs:SQL","channel":"Stored procedure creation or modification with shell invocation (e.g., system(), exec())","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"applicationlogs-sql"}],"mutable_elements":[{"field":"CommandRegex","description":"Regex used to detect suspicious OS commands via SQL"},{"field":"TimeWindow","description":"Window for correlating procedure creation and command execution"}],"live":true,"detection_strategies":["DET0181"],"techniques":["T1505.001"]}],"live":true,"version":"1.0","techniques":["T1505.001"]}],"sigma_rules":[{"id":"9cae055f-e1d2-4f81-b8a5-1986a68cdd84","title":"Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReader","author":"Gregory","status":"test","level":"high","date":"2023-10-11","modified":null,"description":"Detects suspicious \".hta\" file creation in the startup folder by Foxit Reader. This can be an indication of CVE-2023-27363 exploitation.","references":["https://github.com/j00sean/SecBugs/tree/ff72d553f75d93e1a0652830c0f74a71b3f19c46/CVEs/CVE-2023-27363","https://www.zerodayinitiative.com/advisories/ZDI-23-491/","https://www.tarlogic.com/blog/cve-2023-27363-foxit-reader/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.t1505.001","cve.2023-27363","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Exploits/CVE-2023-27363/file_event_win_cve_2023_27363_foxit_rce.yml","techniques":["T1505.001"],"cves":["CVE-2023-27363"]},{"id":"d84c0ded-edd7-4123-80ed-348bb3ccc4d5","title":"Suspicious SQL Query","author":"@juju4","status":"test","level":"medium","date":"2022-12-27","modified":null,"description":"Detects suspicious SQL query keywrods that are often used during recon, exfiltration or destructive activities. Such as dropping tables and selecting wildcard fields","references":["https://github.com/sqlmapproject/sqlmap"],"logsource":{"category":"database"},"tags":["attack.exfiltration","attack.initial-access","attack.privilege-escalation","attack.persistence","attack.t1190","attack.t1505.001"],"path":"rules/category/database/db_anomalous_query.yml","techniques":["T1190","T1505.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}