sqlmap

S0225

Tool.View on attack.mitre.org

About this tool

sqlmap is an open source penetration testing tool that can be used to automate the process of detecting and exploiting SQL injection flaws.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1190
Exploit Public-Facing Application

sqlmap can be used to automate exploitation of SQL injection vulnerabilities.

Groups that use it2

Campaigns1

References1

  1. sqlmap Introduction Open source
    Damele, B., Stampar, M. (n.d.). sqlmap. Retrieved March 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.