SQL Slammer is a worm referenced in DHS NCCIC/ICS-CERT guidance as a notable example of cyber vulnerabilities affecting industrial control system environments. In the provided content, it is cited alongside Stuxnet as a high-profile exploit that helped illustrate ICS cyber risk. The source material does not provide technical details on SQL Slammer’s capabilities, malware family behavior, infection vector, associated threat actor, targeted platforms, industries, or indicators of compromise beyond its use as an example of a worm relevant to ICS security discussions. High-confidence context from the content is limited to its identification as a worm and its mention in relation to ICS vulnerability awareness.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.