pg_hba.conf Rewritten to Trust Auth Then Reloaded (PostGREShell)
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
Microsoft Sentinel (KQL)

