MSSQLSERVER

EventTitleChannelSampleRule
8128Event ID 8128ApplicationYY
15457Event ID 15457ApplicationYY
17103Event ID 17103ApplicationYN
17110Event ID 17110ApplicationYN
17111Event ID 17111ApplicationYN
17125Event ID 17125ApplicationYN
17126Event ID 17126ApplicationYN
17135Launched startup procedure '%s'.ApplicationYY
17137Event ID 17137ApplicationYN
17152Event ID 17152ApplicationYN
17162Event ID 17162ApplicationYN
17164Event ID 17164ApplicationYN
17199Event ID 17199ApplicationYY
17200Event ID 17200ApplicationNY
17201Event ID 17201ApplicationNY
17202Event ID 17202ApplicationNY
17810Event ID 17810ApplicationNY
18454Event ID 18454ApplicationYN
18456Event ID 18456ApplicationYY
18470Event ID 18470ApplicationYY
26067Event ID 26067ApplicationYN
26076Event ID 26076ApplicationYN
33205Event ID 33205ApplicationYY

Event ID 8128

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 8128,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4547,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | Using 'dbghelp.dll' version '4.0.5'</string>\n",
    "Binary": ""
  },
  "message": ""
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Splunk # view in coverage

Event ID 15457

#
Channel
Application
Level
Informational

Fields #

NameDescriptionRules
Data1 detection rule
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 15457,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2019-11-04T09:27:26.315067+00:00",
    "event_record_id": 9696,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "xp_cmdshell",
      "1",
      "0"
    ],
    "Binary": "YTwAAAoAAAAMAAAATQBTAEUARABHAEUAVwBJAE4AMQAwAAAABwAAAG0AYQBzAHQAZQByAAAA"
  },
  "message": ""
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Namecontainsmssql1 rulesigma

Community Notes #

MS SQL Server xp_cmdshell execution. See this DFIR Report write-up: SELECT XMRig FROM SQLServer

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Splunk # view in coverage

References #

Event ID 17103

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17103,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4550,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | Microsoft SQL Server is starting up: launched. Process ID is 0.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17110

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17110,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4551,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | This instance of SQL Server has been using a process ID of 0 since startup.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17111

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17111,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4552,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | Logging SQL Server messages in file 'C:\\\\synthetic\\\\errorlog'.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17125

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17125,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.472630+00:00",
    "event_record_id": 4553,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | Using conventional memory in the memory manager.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17126

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17126,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.442303+00:00",
    "event_record_id": 4540,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | SQL Server is starting at normal priority base (=7).</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17135: Launched startup procedure '%s'.

#
Channel
Application
Level
Informational

Description

SQL Server launched a stored procedure marked for automatic execution at startup (sp_procoption ... 'startup', 'on'). One event is logged per startup procedure each time the instance starts.

Fields #

NameDescription
Data_0Name of the startup stored procedure that was launched.
BinaryBinary event payload (instance and database context).

Example Event #

{
  "system": {
    "provider": "MSSQL$SQLEXPRESS",
    "guid": "",
    "event_source_name": "",
    "event_id": 17135,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-07-06 16:46:29.191311+00:00",
    "event_record_id": 374107,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "dw_startup_probe17135",
    "Binary": "EF4200000A000000180000004A0044002D0044004300300031002D0032003000320032005C00530051004C0045005800500052004500530053000000070000006D00610073007400650072000000"
  },
  "message": "Launched startup procedure 'dw_startup_probe17135'."
}

Community Notes #

Abused for persistence: a startup stored procedure runs in the security context of the SQL Server service account on every instance start. Consumed by the Splunk ESCU 'Windows SQL Server Startup Procedure' analytic, which flags the launched procedure name. Sample captured live from SQL Server 2022 on a lab domain controller; the named instance logs source MSSQL$SQLEXPRESS, while a default instance logs the identical event under source MSSQLSERVER. The procedure name shown is a benign probe used to elicit the event.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk # view in coverage

  • Windows SQL Server Startup Procedure source: This detection identifies when a startup procedure is registered or executed in SQL Server. Startup procedures automatically execute when SQL Server starts, making them an attractive persistence mechanism for attackers. The detection…T1505, T1505.001

References #

Event ID 17137

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17137,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.442303+00:00",
    "event_record_id": 4541,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | Starting up database 'master'.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17152

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17152,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.473648+00:00",
    "event_record_id": 4554,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | The service account is 'NT Service\\\\MSSQLSERVER'.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17162

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17162,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4545,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | SQL Server is now ready for client connections.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17164

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17164,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.473648+00:00",
    "event_record_id": 4555,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | The licensing PID was successfully processed (synthetic).</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 17199

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 17199,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4546,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | Dedicated administrator connection support was not started because it is disabled on this edition.</string>\n",
    "Binary": ""
  },
  "message": ""
}

Detection Patterns #

Event ID 17200

#
Channel
Application

Detection Patterns #

Event ID 17201

#
Channel
Application

Detection Patterns #

Event ID 17202

#
Channel
Application

Detection Patterns #

Event ID 17810

#
Channel
Application

Detection Patterns #

Event ID 18454

#
Channel
Application

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 18454,
    "version": 0,
    "level": 0,
    "task": 4,
    "opcode": 0,
    "keywords": 45035996273704960,
    "time_created": "2019-11-04T09:27:26.127038+00:00",
    "event_record_id": 9690,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "root",
      " [CLIENT: 10.0.2.17]"
    ],
    "Binary": "FkgAAAoAAAAMAAAATQBTAEUARABHAEUAVwBJAE4AMQAwAAAABwAAAG0AYQBzAHQAZQByAAAA"
  },
  "message": ""
}

References #

Event ID 18456

#
Channel
Application

Fields #

NameDescriptionRules
Data21 detection rules
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 18456,
    "version": 0,
    "level": 0,
    "task": 4,
    "opcode": 0,
    "keywords": 40532396646334464,
    "time_created": "2019-11-04T13:46:01.279826+00:00",
    "event_record_id": 13035,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "root",
      " Reason: Password did not match that for the login provided.",
      " [CLIENT: 10.0.2.17]"
    ],
    "Binary": "GEgAAA4AAAAMAAAATQBTAEUARABHAEUAVwBJAE4AMQAwAAAABwAAAG0AYQBzAHQAZQByAAAA"
  },
  "message": ""
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Namecontainsmssql2 rulessigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 18470

#
Channel
Application

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 18470,
    "version": 0,
    "level": 0,
    "task": 4,
    "opcode": 0,
    "keywords": 40532396646334464,
    "time_created": "2026-08-07T00:23:46.628731+00:00",
    "event_record_id": 493490,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "dwhsql_3b7f8f3ea4e64d33bdde63913bbde87b",
    "Data_1": " [CLIENT: <local machine>]",
    "Binary": "264800000E0000000D0000004A0044002D0044004300300031002D0032003000320032000000070000006D00610073007400650072000000"
  },
  "message": ""
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
action_ideqlgfl1 rulesigma
action_ideqlgif1 rulesigma
class_typeeqlx1 rulesigma

Event ID 26067

#
Channel
Application
Level
3

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 26067,
    "version": 0,
    "level": 3,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4549,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | SQL Server Network Interface library could not register SPN (synthetic warning).</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 26076

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 26076,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 01:29:40.457960+00:00",
    "event_record_id": 4548,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>gen_evtx synthetic — do not treat as a real SQL Server event | SQL Server is attempting to register a Service Principal Name (SPN).</string>\n",
    "Binary": ""
  },
  "message": ""
}

Event ID 33205

#
Channel
Application

Fields #

NameDescriptionRules
Data11 detection rules

Example Event #

{
  "system": {
    "provider": "MSSQLSERVER",
    "guid": "",
    "event_source_name": "",
    "event_id": 33205,
    "version": 0,
    "level": 0,
    "task": 4,
    "opcode": 0,
    "keywords": 45035996273704960,
    "time_created": "2019-11-04T09:27:27.315013+00:00",
    "event_record_id": 9707,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "audit_schema_version:1\nevent_time:2019-11-04 09:27:26.3150666\nsequence_number:1\naction_id:LGIS\nsucceeded:true\nis_column_permission:false\nsession_id:58\nserver_principal_id:266\ndatabase_principal_id:0\ntarget_server_principal_id:0\ntarget_database_principal_id:0\nobject_id:0\nuser_defined_event_id:0\ntransaction_id:0\nclass_type:LX\nduration_milliseconds:0\nresponse_rows:0\naffected_rows:0\nclient_ip:10.0.2.17\npermission_bitmask:00000000000000000000000000000000\nsequence_group_id:2D5419DB-389F-4478-946C-23870BA1D2C4\nsession_server_principal_name:root\nserver_principal_name:root\nserver_principal_sid:8867c003d7407345abb6e4ed81382626\ndatabase_principal_name:\ntarget_server_principal_name:\ntarget_server_principal_sid:\ntarget_database_principal_name:\nserver_instance_name:MSEDGEWIN10\ndatabase_name:\nschema_name:\nobject_name:\nstatement:-- network protocol: TCP/IP\r\nset quoted_identifier on\r\nset arithabort off\r\nset numeric_roundabort off\r\nset ansi_warnings on\r\nset ansi_padding on\r\nset ansi_nulls on\r\nset concat_null_yields_null on\r\nset cursor_close_on_commit off\r\nset implicit_transactions off\r\nset language us_english\r\nset dateformat mdy\r\nset datefirst 7\r\nset transaction isolation level read committed\r\n\nadditional_information:<action_info xmlns=\"http://schemas.microsoft.com/sqlserver/2008/sqlaudit_data\"><pooled_connection>1</pooled_connection><client_options>0x28000020</client_options><client_options1>0x0001f438</client_options1><connect_options>0x00000000</connect_options><packet_data_size>8000</packet_data_size><address>10.0.2.17</address><is_dac>0</is_dac></action_info>\nuser_defined_information:\napplication_name:.Net SqlClient Data Provider\n"
    ]
  },
  "message": ""
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Namecontainsmssql4 rulessigma
Datacontainsstatement:exec2 rulessigma
action_ideqal2 rulessigma
action_ideqaprl2 rulessigma
action_ideqdr2 rulessigma
action_ideqg2 rulessigma
action_ideqgwg2 rulessigma
action_ideqlgfl2 rulessigma
action_ideqlgif2 rulessigma
class_typeeqlx2 rulessigma
statementcontainsstate = off2 rulessigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

  • MSSQL Add Account To Sysadmin Role source high: Detects when an attacker tries to backdoor the MSSQL server by adding a backdoor account to the sysadmin fixed server role
  • MSSQL Destructive Query source medium: Detects the invocation of MS SQL transactions that are destructive towards table or database data, such as "DROP TABLE" or "DROP DATABASE".T1485
  • MSSQL Disable Audit Settings source high: Detects when an attacker calls the "ALTER SERVER AUDIT" or "DROP SERVER AUDIT" transaction in order to delete or disable audit logs on the server

References #