LoFP LoFP / t1127

t1127

TitleTags
approved installs of windows sdk with debugging tools for windows (windbg).
direct ps command execution through sqlps.exe is uncommon, childprocess sqlps.exe spawned by sqlagent.exe is a legitimate action.
direct ps command execution through sqltoolsps.exe is uncommon, childprocess sqltoolsps.exe spawned by smss.exe is a legitimate action.
legitimate use
legitimate use for tracing purposes
legitimate use of debugging tools
legitimate use to compile jscript by developers.
possible depending on environment. pair with other factors such as net connections, command-line args, etc.
the build engine is commonly used by windows developers but use by non-engineers is unusual.
these programs may be used by windows developers but use by non-engineers is unusual.
uncommon compiler activity can be due to an engineer running a local build on a production or staging instance in the course of troubleshooting or fixing a software issue.
unknown
unlikely