Definition
Canonical reference for sqli behavior.
Display name
SQL injection attempts
How to read this signal
This annotator represents a behavioral pattern, not a claim of identity.
It’s designed to help you understand why certain traffic looks suspicious, automated,
probing, or exploit-oriented — and to support consistent reporting across the Syndu system.
Explanation
Flags patterns associated with SQL injection probing, including query-logic fragments and suspicious operator/keyword structures in parameters. This annotator supports defensive reporting and helps explain likely exploit probing. Avoid presenting raw payloads verbatim in public-facing UI; prefer summarizing the affected endpoints and frequency over time.