Tag
critical
threat
Microsoft SQL Server Privilege Escalation Vulnerability
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in Microsoft SQL Server 2017, 2019, 2016 and 2022 to execute arbitrary code and gain administrator privileges.
SQL Server 2016 +3
privilege-escalation
execution
mssql
2r
2t
medium
advisory
Potential Veeam Credential Access via SQL Commands
2 rules 5 TTPsAttackers can leverage sqlcmd.exe or PowerShell commands like Invoke-Sqlcmd to access Veeam credentials stored in MSSQL databases, potentially targeting backups for destructive operations such as ransomware attacks.
Microsoft Defender XDR +1
veeam
credential-access
mssql
windows
ransomware
2r
5t
medium
advisory
MSSQL xp_cmdshell Stored Procedure Abuse for Persistence and Execution
2 rules 2 TTPsAttackers leverage the MSSQL xp_cmdshell stored procedure to execute arbitrary commands, escalating privileges and establishing persistence on Windows systems.
SQL Server
mssql
xp_cmdshell
persistence
execution
2r
2t