Rule Info
Name
PostgreSQL Connection String Enumeration via Grep
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the use of grep to search for PostgreSQL connection strings and database URLs, which may indicate credential harvesting from application directories as a precursor to lateral movement or data exfiltration.
Attackers may use this technique to find hardcoded database credentials in source code, configuration files, or environment variable definitions.
Date
2026-08-07 00:00:00
Modified
None
Id
7b3f2e91-0d4c-4a58-b7e6-5c8d1f9a3e02
Tags
attack.credential-access attack.discovery attack.t1552.001 attack.collection attack.t1213
Type
Nextron Sigma feed only (private)
