Veeam PostgreSQL credential extraction via psql.exe
This rule detects the suspicious execution of the psql.exe command-line client interacting with the Veeam Backup database. It specifically monitors for attempts to query database tables containing sensitive user_name and password information, often correlated with WMI or encoded PowerShell execution, which suggests an attempt to extract credentials from backup software.
Microsoft Sentinel (KQL)

