← LibraryTechnique entry
W-NOSQLICollection
NoSQL Injection (MongoDB)
{"$ne": null} / {"$gt": ""} operator injection bypasses login or extracts data field by field.
§ Where this technique fits
W-NOSQLI is catalogued under the Collection tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01Exfiltration Over C2 Channelseen 1×T1041 · Exfiltration
- 02Valid Accountsseen 1×T1078 · Initial Access