Ticket summary
On 14 March 2026 the FastCart SOC received a medium-severity ticket: AWS WAF COUNT metrics for SQL injection signatures increased on the production shopfront. No customer data has been confirmed stolen. You are the investigating analyst.
FastCart operates a public e-commerce storefront behind AWS WAF and an Application Load Balancer. The Web ACL uses AWS Managed Rules for SQL injection, but several rules were left in COUNT during a recent tuning window.
At 11:05 UTC an on-call engineer noticed a spike in SQLi_QUERYARGUMENTS COUNT samples and opened IR-2026-0314-014. You have been given a two-source export covering the morning traffic window: WAF JSON logs and ALB access logs.
Your job is to reconstruct the campaign, determine whether any payload bypassed WAF and reached the application, and recommend an immediate hardening action.