Veeam Backup RCE - Suspicious Child Process, LSASS Access, and Backup Destruction
Detects suspicious activities within a Veeam backup environment, including unauthorized process spawning by Veeam services, LSASS memory access, destruction of backup catalogs or restore points via PowerShell, and unauthorized access to Veeam database files by non-Veeam processes.
Microsoft Sentinel (KQL)

