RULE(RULE ID:332779)

Rule General Information
Release Date: 2021-03-11
Rule Name: Scanner Sqlmap Detected
Severity:
CVE ID:
Rule Protection Details
Description: SQLMap is an open source penetration testing tool that can perform automated detection and use SQL injection extensions to gain access to the database server. This rule detects SQLMap scanner traffic characteristics.
Impact: The attacker uses the scanner to obtain information and prepare for the next attack.
Affected OS: Windows, Linux, Others
Reference:
Solutions
If it is an authorized test, there is no need to deal with it, otherwise it is recommended to block the source IP.