Windows Process: sqlcmd.exe Querying Veeam Backup Databases

Flags sqlcmd.exe command lines querying Veeam backup database objects associated with repository and credential data.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-04
Updated
2026-07-30

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows process executions of sqlcmd.exe that issue SQL queries against Veeam backup database objects. Attackers may use direct database querying to collect sensitive configuration or credential-related information from exposed backup repositories. The detection relies on process creation telemetry, matching sqlcmd.exe execution paths and command-line arguments containing Veeam database context markers.

Related detections9 linkedT1005 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious RDP Bitmap Cache Temp Files Written by mstsc in Rogue RDP Campaign (via file_event)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
Windows Process: sqlcmd.exe Querying Veeam Backup Databases
Pivot detection · T1005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.