Data Export From MSSQL Table Via BCP.EXE — Detection Rule

Detects the execution of the BCP utility in order to export data from the database. Attackers were seen saving their malware to a database column or table and then later extracting it via "bcp.exe" into a file.

Read the full analysis on IntelFusions