SQLPS.exe
Sources: 300M+ executions observed in the wild.
Summary
SQL Server PowerShell - launches a PowerShell session with SQL Server modules pre-loaded. Deprecated in favor of the SqlServer PowerShell module.
SQLPS.exe is the 1045th most commonly executed Windows program in EchoTrail's dataset, observed 1,832 times across enterprise environments. It typically runs from D:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn.
Get this in your tools
The same record for sqlps.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/sqlps.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- D:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn34.55%
- D:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn20.58%
- D:\Program Files (x86)\Microsoft SQL Server\160\Tools\Binn19.71%
- D:\Program Files (x86)\Microsoft SQL Server\140\Tools\Binn8.73%
- C:\Program Files (x86)\Microsoft SQL Server\150\Tools\Binn6.66%
- D:\Program Files (x86)\Microsoft SQL Server\130\Tools\Binn4.2%
- D:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn4.04%
- C:\Program Files (x86)\Microsoft SQL Server\160\Tools\Binn1.53%
Top Hashes (SHA256)
- 484c16df0d32a6aaaa2012d90fac9a25abeb00932a5e787cbccd9e86aac0cfa827.24%
- 6e710aa1bc36ce87c5363fd9b3e6e3fb60d9140aa8d35c458a9f9ff046cb94a226.26%
- 9777e3c68f5234a3f36ed94315e3d6fc5332a5a6df44a6d8fcd6136a79af1da221.23%
- 615f14eca159504bdc028d9f2ec860f0f8e5edad8cb7835e0e2eda62780f3cf08.73%
- 37cefa6d31e5c86778cdcb0ccbfdcbd382df4d2ba36dac3ff0777e28b7deaf686.88%
- 37fecadb69152dfc57c98863c374a4804d8abb3f19fc4314416bfea2d0eb7ca34.2%
- 8020d5f05aaf8b30c0bcb389a848c1ba6d08639388cd355a7ae0f7e3358df3494.04%
- ee04872bb3e8b68bcaaa896ae41a74167f72092f0a49c3ee62b4447ffa0d6db31.42%
Security Analysis
What does SQLPS.exe normally do?
Used by SQL Server for PowerShell-based management tasks. May be invoked by SQL Server Agent jobs.
When is SQLPS.exe suspicious?
Running on systems without SQL Server. Executing encoded commands. Loading modules unrelated to SQL Server.
How do attackers abuse SQLPS.exe?
sqlps.exe is a signed Microsoft binary that launches PowerShell without the usual PowerShell protections (AMSI, Constrained Language Mode). Attackers on SQL Server machines use it to bypass PowerShell security controls and execute arbitrary code.
Detection guidance
Monitor sqlps.exe for non-SQL-related command execution. Alert on encoded commands or execution of scripts unrelated to SQL administration.
False positive notes
Legitimate on SQL Server machines for database administration tasks and SQL Agent jobs.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about SQLPS.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for SQLPS.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.