T-7002validated
Database Extraction
Extract data from databases via SQL injection or authorized database tool access
Tactic
Collection (Stage 7)
Gather and stage data from databases, file systems, and APIs
Attack Class
CODE-INJECTION
Injecting and executing arbitrary code through SQL injection, command injection, or code generation
Evidence
validated
Reproduced in controlled lab environment (DVAA) with documented steps.
DVAA Validation
DataBot SQL injection
Detection (HackMyAgent)
IO-001INJ-001INJ-002INJ-003
npx hackmyagent secure --ciDefense (OASB Controls)
OASB 4.1OASB 4.2OASB 4.3OASB 4.4
How to Cite
AI Agent Threat Matrix T-7002 (Database Extraction). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-7002