Havij
MITRE ATT&CK: S0224 View on attack.mitre.org
- Malware type
- exploit-kit
- Profile updated
- 2026-07-07 15:33:03
Context
Havij is an automatic SQL Injection tool distributed by the Iranian ITSecTeam security company. Havij has been used by penetration testers and adversaries.
Detection coverage
- 46 Sigma rules
Malware & tools used
- Exploit Public-Facing Application (attack-pattern)
Used by threat actors
- Ajax Security Team (threat-actor)
Reports & references
- MITRE ATT&CK — S0224 (report)
- blog.checkpoint.com — Analysis Havij Sql Injection Tool (report)