Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects instances where a non-root user executes commands containing 'acronis' alongside web hosting management keywords (cpanel, whm, plesk) while the target process user is 'root'. This behavior suggests an attempt to abuse backup software or administrative management tools to escalate privileges or perform unauthorized administrative actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects the suspicious execution of the psql.exe command-line client interacting with the Veeam Backup database. It specifically monitors for attempts to query database tables containing sensitive user_name and password information, often correlated with WMI or encoded PowerShell execution, which suggests an attempt to extract credentials from backup software.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
102