Postgres Process Executes OS Commands via COPY TO PROGRAM

Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().