SQL Stored Procedures

T1505.001

Sub-technique of T1505 Server Software Component.View on attack.mitre.org

About this technique

Adversaries may abuse SQL stored procedures to establish persistent access to systems. SQL Stored Procedures are code that can be saved and reused so that database users do not waste time rewriting frequently used SQL queries. Stored procedures can be invoked via SQL statements to the database using the procedure name or via defined events (e.g. when a SQL server application is started/restarted).

Adversaries may craft malicious stored procedures that can provide a persistence mechanism in SQL database servers. To execute operating system commands through SQL syntax the adversary may have to enable additional functionality, such as xp_cmdshell for MSSQL Server.

Microsoft SQL Server can enable common language runtime (CLR) integration. With CLR integration enabled, application developers can write stored procedures using any .NET framework language (e.g. VB .NET, C#, etc.). Adversaries may craft or modify CLR assemblies that are linked to stored procedures since these CLR assemblies can be made to execute arbitrary commands.

Detection rules7

Rules on DetectionCode tagged with T1505.001.

Sigma1

RuleLevelLog source
Suspicious SQL QuerymediumNULL / database

Splunk6

RuleTypeRiskData source
Windows SQL Server Configuration Option HuntHuntingNULLWindows Event Log Application 15457
Windows SQL Server Critical Procedures EnabledTTPNULLWindows Event Log Application 15457
Windows SQL Server Extended Procedure DLL Loading HuntHuntingNULLWindows Event Log Application 8128
Windows SQL Server Startup ProcedureAnomalyNULLWindows Event Log Application 17135
Windows SQL Server xp_cmdshell Config ChangeTTPNULLWindows Event Log Application 15457
Windows Sqlservr Spawning ShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688

Groups0

None recorded.

Software1

Campaigns1

Procedure examples2

Software1

Used byProcedure example
MalwareStuxnet

Stuxnet used xp_cmdshell to store and execute SQL code.

Campaigns1

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used various MS-SQL stored procedures.

References5

  1. Kaspersky MSSQL Aug 2019 Open source
    Plakhov, A., Sitchikhin, D. (2019, August 22). Agent 1433: remote attack on Microsoft SQL Server. Retrieved September 4, 2019.
  2. Microsoft CLR Integration 2017 Open source
    Microsoft. (2017, June 19). Common Language Runtime Integration. Retrieved July 8, 2019.
  3. Microsoft xp_cmdshell 2017 Open source
    Microsoft. (2017, March 15). xp_cmdshell (Transact-SQL). Retrieved September 9, 2019.
  4. NetSPI SQL Server CLR Open source
    Sutherland, S. (2017, July 13). Attacking SQL Server CLR Assemblies. Retrieved September 12, 2024.
  5. NetSPI Startup Stored Procedures Open source
    Sutherland, S. (2016, March 7). Maintaining Persistence via SQL Server – Part 1: Startup Stored Procedures. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.