Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo

Alerts on sqlcmd.exe running a query targeting the VeeamBackup dbo Credentials table to dump sensitive credentials.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-20
Updated
2026-07-30

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process executions of sqlcmd.exe where the command line contains a SQL query selecting the TOP rows from the VeeamBackup dbo Credentials table. Such credential-dumping activity matters because it enables attackers to obtain sensitive backup database secrets, often as a step toward further compromise. Detection relies on Windows process creation telemetry capturing the sqlcmd.exe image path and the full command line content.

Related detections9 linkedT1005 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious RDP Bitmap Cache Temp Files Written by mstsc in Rogue RDP Campaign (via file_event)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo
Pivot detection · T1005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.