Suspicious Activity Involving Microsoft SQL Server
Attackers are weaponizing built-in SQL Server features like xp_cmdshell and CLR integration to turn database access into full host compromise, then pivot into hybrid cloud environments through managed identities and metadata services.