ISIT Security LabsIncident response training

FastCart · shop.fastcart.io

AWS WAF SQL Injection Attack Investigation

Intermediate45 minCloud Detection & Response
Now: Case briefing. Read the ticket and environment first. Do not open logs until you know what you are looking for.

Ticket summary

On 14 March 2026 the FastCart SOC received a medium-severity ticket: AWS WAF COUNT metrics for SQL injection signatures increased on the production shopfront. No customer data has been confirmed stolen. You are the investigating analyst.

FastCart operates a public e-commerce storefront behind AWS WAF and an Application Load Balancer. The Web ACL uses AWS Managed Rules for SQL injection, but several rules were left in COUNT during a recent tuning window.

At 11:05 UTC an on-call engineer noticed a spike in SQLi_QUERYARGUMENTS COUNT samples and opened IR-2026-0314-014. You have been given a two-source export covering the morning traffic window: WAF JSON logs and ALB access logs.

Your job is to reconstruct the campaign, determine whether any payload bypassed WAF and reached the application, and recommend an immediate hardening action.