Veeam Backup Credential Extraction via psql.exe Query
Detects the execution of psql.exe to query the Veeam Backup & Replication PostgreSQL database for stored credentials. This pattern is associated with credential theft techniques utilized during ransomware operations (e.g., Bumblebee, Akira) where sensitive configuration or credential data is retrieved and potentially later decrypted via DPAPI.
Sigma

