Veeam Credential Extraction via psql.exe Querying VeeamBackup Database
Detects unauthorized attempts to access or interact with the Veeam Backup database, including psql.exe direct queries, PowerShell scripts attempting to decrypt credentials using DPAPI, and encoded PowerShell commands launched from cmd.exe that target the Veeam environment.
Cortex XDR

