Detection: selection_parent: ParentImage|endswith:
'\sqlps.exe' selection_image: Image|endswith:'\sqlps.exe'OriginalFileName:'sqlps.exe'filter_image: ParentImage|endswith:
'\sqlagent.exe' condition:selection_parent or (selection_image and not filter_image) Falsepositives:
-Direct PS command execution through SQLPS.exe is uncommon, childprocess sqlps.exe spawned by sqlagent.exe is a legitimate action. Level:medium