LoFP LoFP / t1127

t1127

TitleTags
although unlikely, limited instances have been identified coming from native microsoft utilities similar to sccm.
although unlikely, some legitimate applications may use a moved copy of microsoft.workflow.compiler.exe, triggering a false positive.
approved installs of windows sdk with debugging tools for windows (windbg).
direct ps command execution through sqlps.exe is uncommon, childprocess sqlps.exe spawned by sqlagent.exe is a legitimate action.
direct ps command execution through sqltoolsps.exe is uncommon, childprocess sqltoolsps.exe spawned by smss.exe is a legitimate action.
legitimate use
legitimate use by a software developer
legitimate use for tracing purposes
legitimate use of debugging tools
legitimate use to compile jscript by developers.
possible depending on environment. pair with other factors such as net connections, command-line args, etc.
the build engine is commonly used by windows developers but use by non-engineers is unusual. if a build system triggers this rule it can be exempted by process, user or host name.
these programs may be used by windows developers but use by non-engineers is unusual.
unlikely