Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Contributors
1
1
Categories
2
1
1
1
1
Platforms
1
1
Products / Services
1
1
1
1
MITRE Techniques
17,957
15,455
12,307
8,184
6,031
Detects instances where a non-root user executes commands containing 'acronis' alongside web hosting management keywords (cpanel, whm, plesk) while the target process user is 'root'. This behavior suggests an attempt to abuse backup software or administrative management tools to escalate privileges or perform unauthorized administrative actions.
This rule detects the suspicious execution of the psql.exe command-line client interacting with the Veeam Backup database. It specifically monitors for attempts to query database tables containing sensitive user_name and password information, often correlated with WMI or encoded PowerShell execution, which suggests an attempt to extract credentials from backup software.

