But since the question was one of a live monitor that detects intrusion, I've never heard of such a thing. There's always the possibility of aliasing `mysqldump' or `pg_dump' to another command that emails your admins, or other manual commands that shouldn't be run throughout the course of the day. My personal boxes run such an email script anytime someone logs in as root, and emails the logfile anytime someone uses sudo. That won't help against SQLi, but might against RCE that's allowed someone to tunnel into your box.
But, in the long run, there's nothing that won't beat subscribing the the security lists of all the software you run to get immediate notice of any vulnerabilities, hiring a pen tester, and stopping every day to read the code you've written to discover what kind of edge cases might help an attacker compromise your system.