Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2022-10-18 13:41:11 -07:00
committed by GitHub
179 changed files with 2020 additions and 585 deletions
+241 -287
View File
@@ -1,92 +1,57 @@
lolbas_file_name,lolbas_file_path,description
regsvcs.exe,c:\windows\system32\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
regsvcs.exe,c:\windows\syswow64\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
ftp.exe,c:\windows\system32\*,A binary designed for connecting to FTP servers
ftp.exe,c:\windows\syswow64\*,A binary designed for connecting to FTP servers
dfsvc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET
offlinescannershell.exe,c:\program files\windows defender\offline\*,Windows Defender Offline Shell
eventvwr.exe,c:\windows\system32\*,Displays Windows Event Logs in a GUI window.
eventvwr.exe,c:\windows\syswow64\*,Displays Windows Event Logs in a GUI window.
rasautou.exe,c:\windows\system32\*,Windows Remote Access Dialer
schtasks.exe,c:\windows\system32\*,Schedule periodic tasks
schtasks.exe,c:\windows\syswow64\*,Schedule periodic tasks
certreq.exe,c:\windows\system32\*,Used for requesting and managing certificates
certreq.exe,c:\windows\syswow64\*,Used for requesting and managing certificates
pktmon.exe,c:\windows\system32\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
pktmon.exe,c:\windows\syswow64\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
unregmp2.exe,c:\windows\system32\*,Microsoft Windows Media Player Setup Utility
unregmp2.exe,c:\windows\syswow64\*,Microsoft Windows Media Player Setup Utility
wlrmdr.exe,c:\windows\system32\*,Windows Logon Reminder executable
xwizard.exe,c:\windows\system32\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
xwizard.exe,c:\windows\syswow64\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
findstr.exe,c:\windows\system32\*,"Write to ADS, discover, or download files with Findstr.exe"
findstr.exe,c:\windows\syswow64\*,"Write to ADS, discover, or download files with Findstr.exe"
esentutl.exe,c:\windows\system32\*,Binary for working with Microsoft Joint Engine Technology (JET) database
esentutl.exe,c:\windows\syswow64\*,Binary for working with Microsoft Joint Engine Technology (JET) database
cscript.exe,c:\windows\system32\*,Binary used to execute scripts in Windows
cscript.exe,c:\windows\syswow64\*,Binary used to execute scripts in Windows
reg.exe,c:\windows\system32\*,Used to manipulate the registry
reg.exe,c:\windows\syswow64\*,Used to manipulate the registry
imewdbld.exe,c:\windows\system32\ime\shared\*,Microsoft IME Open Extended Dictionary Module
csc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile C# code
csc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile C# code
pnputil.exe,c:\windows\system32\*,Used for installing drivers
atbroker.exe,c:\windows\system32\*,Helper binary for Assistive Technology (AT)
atbroker.exe,c:\windows\syswow64\*,Helper binary for Assistive Technology (AT)
datasvcutil.exe,c:\windows\microsoft.net\framework64\v3.5\*,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
appinstaller.exe,c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\*,Tool used for installation of AppX/MSIX applications on Windows 10
print.exe,c:\windows\system32\*,Used by Windows to send files to the printer
print.exe,c:\windows\syswow64\*,Used by Windows to send files to the printer
winget.exe,c:\users\user\appdata\local\microsoft\windowsapps\*,Windows Package Manager tool
pcwrun.exe,c:\windows\system32\*,Program Compatibility Wizard
vbc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used for compile vbs code
vbc.exe,c:\windows\microsoft.net\framework64\v3.5\*,Binary file used for compile vbs code
diantz.exe,c:\windows\system32\*,Binary that package existing files into a cabinet (.cab) file
diantz.exe,c:\windows\syswow64\*,Binary that package existing files into a cabinet (.cab) file
rpcping.exe,c:\windows\system32\*,Used to verify rpc connection
rpcping.exe,c:\windows\syswow64\*,Used to verify rpc connection
wsreset.exe,c:\windows\system32\*,Used to reset Windows Store settings according to its manifest file
ttdinject.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
ttdinject.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
ilasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,used for compile c# code into dll or exe.
ilasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,used for compile c# code into dll or exe.
rdrleakdiag.exe,c:\windows\system32\*,Microsoft Windows resource leak diagnostic tool
rdrleakdiag.exe,c:\windows\syswow64\*,Microsoft Windows resource leak diagnostic tool
certutil.exe,c:\windows\system32\*,Windows binary used for handling certificates
certutil.exe,c:\windows\syswow64\*,Windows binary used for handling certificates
replace.exe,c:\windows\system32\*,Used to replace file with another file
replace.exe,c:\windows\syswow64\*,Used to replace file with another file
mshta.exe,c:\windows\system32\*,Used by Windows to execute html applications. (.hta)
mshta.exe,c:\windows\syswow64\*,Used by Windows to execute html applications. (.hta)
bitsadmin.exe,c:\windows\system32\*,Used for managing background intelligent transfer
bitsadmin.exe,c:\windows\syswow64\*,Used for managing background intelligent transfer
wscript.exe,c:\windows\system32\*,Used by Windows to execute scripts
wscript.exe,c:\windows\syswow64\*,Used by Windows to execute scripts
certoc.exe,c:\windows\system32\*,Used for installing certificates
certoc.exe,c:\windows\syswow64\*,Used for installing certificates
ssh.exe,c:\windows\system32\openssh\*,Ssh.exe is the OpenSSH compatible client can be used to connect to Windows 10 (build 1809 and later) and Windows Server 2019 devices.
ieexec.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
ieexec.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
cmd.exe,c:\windows\system32\*,The command-line interpreter in Windows
cmd.exe,c:\windows\syswow64\*,The command-line interpreter in Windows
microsoft.workflow.compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,A utility included with .NET that is capable of compiling and executing C# or VB.net code.
cmdl32.exe,c:\windows\system32\*,Microsoft Connection Manager Auto-Download
cmdl32.exe,c:\windows\syswow64\*,Microsoft Connection Manager Auto-Download
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\*,Execute target PowerShell script
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\*,Execute target PowerShell script
printbrm.exe,c:\windows\system32\spool\tools\*,Printer Migration Command-Line Tool
makecab.exe,c:\windows\system32\*,Binary to package existing files into a cabinet (.cab) file
makecab.exe,c:\windows\syswow64\*,Binary to package existing files into a cabinet (.cab) file
customshellhost.exe,c:\windows\system32\*,A host process that is used by custom shells when using Windows in Kiosk mode.
forfiles.exe,c:\windows\system32\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
forfiles.exe,c:\windows\syswow64\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
devicecredentialdeployment.exe,c:\windows\system32\*,Device Credential Deployment
desktopimgdownldr.exe,c:\windows\system32\*,Windows binary used to configure lockscreen/desktop image
aspnet_compiler.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ASP.NET Compilation Tool
aspnet_compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ASP.NET Compilation Tool
regedit.exe,c:\windows\system32\*,Used by Windows to manipulate registry
regedit.exe,c:\windows\syswow64\*,Used by Windows to manipulate registry
regsvr32.exe,c:\windows\system32\*,Used by Windows to register dlls
regsvr32.exe,c:\windows\syswow64\*,Used by Windows to register dlls
control.exe,c:\windows\system32\*,Binary used to launch controlpanel items in Windows
control.exe,c:\windows\syswow64\*,Binary used to launch controlpanel items in Windows
configsecuritypolicy.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
scriptrunner.exe,c:\windows\system32\*,Execute binary through proxy binary to evade defensive counter measures
scriptrunner.exe,c:\windows\syswow64\*,Execute binary through proxy binary to evade defensive counter measures
offlinescannershell.exe,c:\program files\windows defender\offline\*,Windows Defender Offline Shell
atbroker.exe,c:\windows\system32\*,Helper binary for Assistive Technology (AT)
atbroker.exe,c:\windows\syswow64\*,Helper binary for Assistive Technology (AT)
mmc.exe,c:\windows\system32\*,Load snap-ins to locally and remotely manage Windows systems
mmc.exe,c:\windows\syswow64\*,Load snap-ins to locally and remotely manage Windows systems
mavinject.exe,c:\windows\system32\*,Used by App-v in Windows
mavinject.exe,c:\windows\syswow64\*,Used by App-v in Windows
ftp.exe,c:\windows\system32\*,A binary designed for connecting to FTP servers
ftp.exe,c:\windows\syswow64\*,A binary designed for connecting to FTP servers
ttdinject.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
ttdinject.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
certoc.exe,c:\windows\system32\*,Used for installing certificates
certoc.exe,c:\windows\syswow64\*,Used for installing certificates
at.exe,c:\windows\system32\*,Schedule periodic tasks
at.exe,c:\windows\syswow64\*,Schedule periodic tasks
netsh.exe,c:\windows\system32\*,Netsh is a Windows tool used to manipulate network interface settings.
netsh.exe,c:\windows\syswow64\*,Netsh is a Windows tool used to manipulate network interface settings.
pnputil.exe,c:\windows\system32\*,Used for installing drivers
ie4uinit.exe,c:\windows\system32\*,Executes commands from a specially prepared ie4uinit.inf file.
ie4uinit.exe,c:\windows\syswow64\*,Executes commands from a specially prepared ie4uinit.inf file.
infdefaultinstall.exe,c:\windows\system32\*,Binary used to perform installation based on content inside inf files
infdefaultinstall.exe,c:\windows\syswow64\*,Binary used to perform installation based on content inside inf files
forfiles.exe,c:\windows\system32\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
forfiles.exe,c:\windows\syswow64\*,Selects and executes a command on a file or set of files. This command is useful for batch processing.
register-cimprovider.exe,c:\windows\system32\*,Used to register new wmi providers
register-cimprovider.exe,c:\windows\syswow64\*,Used to register new wmi providers
tttracer.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel
tttracer.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel
xwizard.exe,c:\windows\system32\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
xwizard.exe,c:\windows\syswow64\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe
pcalua.exe,c:\windows\system32\*,Program Compatibility Assistant
print.exe,c:\windows\system32\*,Used by Windows to send files to the printer
print.exe,c:\windows\syswow64\*,Used by Windows to send files to the printer
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\*,Execute target PowerShell script
runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\*,Execute target PowerShell script
regasm.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Part of .NET
cmd.exe,c:\windows\system32\*,The command-line interpreter in Windows
cmd.exe,c:\windows\syswow64\*,The command-line interpreter in Windows
msbuild.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework\v3.5\*,Used to compile and execute code
@@ -94,69 +59,18 @@ msbuild.exe,c:\windows\microsoft.net\framework64\v3.5\*,Used to compile and exec
msbuild.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Used to compile and execute code
msbuild.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Used to compile and execute code
msbuild.exe,c:\program files (x86)\msbuild\14.0\bin\*,Used to compile and execute code
register-cimprovider.exe,c:\windows\system32\*,Used to register new wmi providers
register-cimprovider.exe,c:\windows\syswow64\*,Used to register new wmi providers
fltmc.exe,c:\windows\system32\*,Filter Manager Control Program used by Windows
tttracer.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel
tttracer.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel
ie4uinit.exe,c:\windows\system32\*,Executes commands from a specially prepared ie4uinit.inf file.
ie4uinit.exe,c:\windows\syswow64\*,Executes commands from a specially prepared ie4uinit.inf file.
fsutil.exe,c:\windows\system32\*,File System Utility
fsutil.exe,c:\windows\syswow64\*,File System Utility
sc.exe,c:\windows\system32\*,Used by Windows to manage services
sc.exe,c:\windows\syswow64\*,Used by Windows to manage services
conhost.exe,c:\windows\system32\*,Console Window host
bash.exe,c:\windows\system32\*,File used by Windows subsystem for Linux
bash.exe,c:\windows\syswow64\*,File used by Windows subsystem for Linux
hh.exe,c:\windows\*,Binary used for processing chm files in Windows
hh.exe,c:\windows\syswow64\*,Binary used for processing chm files in Windows
settingsynchost.exe,c:\windows\system32\*,Host Process for Setting Synchronization
settingsynchost.exe,c:\windows\syswow64\*,Host Process for Setting Synchronization
finger.exe,c:\windows\system32\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
finger.exe,c:\windows\syswow64\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
cmstp.exe,c:\windows\system32\*,Installs or removes a Connection Manager service profile.
cmstp.exe,c:\windows\syswow64\*,Installs or removes a Connection Manager service profile.
mmc.exe,c:\windows\system32\*,Load snap-ins to locally and remotely manage Windows systems
mmc.exe,c:\windows\syswow64\*,Load snap-ins to locally and remotely manage Windows systems
jsc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
configsecuritypolicy.exe,c:\program files\windows defender\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
configsecuritypolicy.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
stordiag.exe,c:\windows\system32\*,Storage diagnostic tool
stordiag.exe,c:\windows\syswow64\*,Storage diagnostic tool
scriptrunner.exe,c:\windows\system32\*,Execute binary through proxy binary to evade defensive counter measures
scriptrunner.exe,c:\windows\syswow64\*,Execute binary through proxy binary to evade defensive counter measures
odbcconf.exe,c:\windows\system32\*,Used in Windows for managing ODBC connections
odbcconf.exe,c:\windows\syswow64\*,Used in Windows for managing ODBC connections
certutil.exe,c:\windows\system32\*,Windows binary used for handling certificates
certutil.exe,c:\windows\syswow64\*,Windows binary used for handling certificates
vbc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used for compile vbs code
vbc.exe,c:\windows\microsoft.net\framework64\v3.5\*,Binary file used for compile vbs code
psr.exe,c:\windows\system32\*,"Windows Problem Steps Recorder, used to record screen and clicks."
psr.exe,c:\windows\syswow64\*,"Windows Problem Steps Recorder, used to record screen and clicks."
extexport.exe,c:\program files\internet explorer\*,Load a DLL located in the c:\test folder with a specific name.
extexport.exe,c:\program files (x86)\internet explorer\*,Load a DLL located in the c:\test folder with a specific name.
rpcping.exe,c:\windows\system32\*,Used to verify rpc connection
rpcping.exe,c:\windows\syswow64\*,Used to verify rpc connection
msdt.exe,c:\windows\system32\*,Microsoft diagnostics tool
msdt.exe,c:\windows\syswow64\*,Microsoft diagnostics tool
workfolders.exe,c:\windows\system32\*,Work Folders
diskshadow.exe,c:\windows\system32\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
diskshadow.exe,c:\windows\syswow64\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
extrac32.exe,c:\windows\system32\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
extrac32.exe,c:\windows\syswow64\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
eventvwr.exe,c:\windows\system32\*,Displays Windows Event Logs in a GUI window.
eventvwr.exe,c:\windows\syswow64\*,Displays Windows Event Logs in a GUI window.
mavinject.exe,c:\windows\system32\*,Used by App-v in Windows
mavinject.exe,c:\windows\syswow64\*,Used by App-v in Windows
regasm.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Part of .NET
regasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Part of .NET
gpscript.exe,c:\windows\system32\*,Used by group policy to process scripts
gpscript.exe,c:\windows\syswow64\*,Used by group policy to process scripts
rundll32.exe,c:\windows\system32\*,Used by Windows to execute dll files
rundll32.exe,c:\windows\syswow64\*,Used by Windows to execute dll files
regsvr32.exe,c:\windows\system32\*,Used by Windows to register dlls
regsvr32.exe,c:\windows\syswow64\*,Used by Windows to register dlls
regedit.exe,c:\windows\system32\*,Used by Windows to manipulate registry
regedit.exe,c:\windows\syswow64\*,Used by Windows to manipulate registry
msiexec.exe,c:\windows\system32\*,Used by Windows to execute msi files
msiexec.exe,c:\windows\syswow64\*,Used by Windows to execute msi files
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\64kb6472.inf_amd64_3daef03bbe98572b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_0e9c57ae3396e055\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_209bd95d56b1ac2d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
@@ -313,133 +227,184 @@ gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132544.i
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132574.inf_amd64_54c9b905b975ee55\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132869.inf_amd64_052eb72d070df60f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\kit126731.inf_amd64_1905c9d5f38631d9\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path."
wuauclt.exe,c:\windows\system32\*,Windows Update Client
presentationhost.exe,c:\windows\system32\*,File is used for executing Browser applications
presentationhost.exe,c:\windows\syswow64\*,File is used for executing Browser applications
regini.exe,c:\windows\system32\*,Used to manipulate the registry
regini.exe,c:\windows\syswow64\*,Used to manipulate the registry
dnscmd.exe,c:\windows\system32\*,A command-line interface for managing DNS servers
dnscmd.exe,c:\windows\syswow64\*,A command-line interface for managing DNS servers
wab.exe,c:\program files\windows mail\*,Windows address book manager
wab.exe,c:\program files (x86)\windows mail\*,Windows address book manager
msconfig.exe,c:\windows\system32\*,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows"
wscript.exe,c:\windows\system32\*,Used by Windows to execute scripts
wscript.exe,c:\windows\syswow64\*,Used by Windows to execute scripts
makecab.exe,c:\windows\system32\*,Binary to package existing files into a cabinet (.cab) file
makecab.exe,c:\windows\syswow64\*,Binary to package existing files into a cabinet (.cab) file
datasvcutil.exe,c:\windows\microsoft.net\framework64\v3.5\*,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
cmdl32.exe,c:\windows\system32\*,Microsoft Connection Manager Auto-Download
cmdl32.exe,c:\windows\syswow64\*,Microsoft Connection Manager Auto-Download
mshta.exe,c:\windows\system32\*,Used by Windows to execute html applications. (.hta)
mshta.exe,c:\windows\syswow64\*,Used by Windows to execute html applications. (.hta)
cmdkey.exe,c:\windows\system32\*,"creates, lists, and deletes stored user names and passwords or credentials."
cmdkey.exe,c:\windows\syswow64\*,"creates, lists, and deletes stored user names and passwords or credentials."
ilasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,used for compile c# code into dll or exe.
ilasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,used for compile c# code into dll or exe.
rdrleakdiag.exe,c:\windows\system32\*,Microsoft Windows resource leak diagnostic tool
rdrleakdiag.exe,c:\windows\syswow64\*,Microsoft Windows resource leak diagnostic tool
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.4-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.7-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender
wmic.exe,c:\windows\system32\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
wmic.exe,c:\windows\syswow64\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
jsc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format
cmstp.exe,c:\windows\system32\*,Installs or removes a Connection Manager service profile.
cmstp.exe,c:\windows\syswow64\*,Installs or removes a Connection Manager service profile.
stordiag.exe,c:\windows\system32\*,Storage diagnostic tool
stordiag.exe,c:\windows\syswow64\*,Storage diagnostic tool
odbcconf.exe,c:\windows\system32\*,Used in Windows for managing ODBC connections
odbcconf.exe,c:\windows\syswow64\*,Used in Windows for managing ODBC connections
wlrmdr.exe,c:\windows\system32\*,Windows Logon Reminder executable
printbrm.exe,c:\windows\system32\spool\tools\*,Printer Migration Command-Line Tool
dfsvc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET
dfsvc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET
extrac32.exe,c:\windows\system32\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
extrac32.exe,c:\windows\syswow64\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe"
rundll32.exe,c:\windows\system32\*,Used by Windows to execute dll files
rundll32.exe,c:\windows\syswow64\*,Used by Windows to execute dll files
runonce.exe,c:\windows\system32\*,Executes a Run Once Task that has been configured in the registry
runonce.exe,c:\windows\syswow64\*,Executes a Run Once Task that has been configured in the registry
syncappvpublishingserver.exe,c:\windows\system32\*,Used by App-v to get App-v server lists
syncappvpublishingserver.exe,c:\windows\syswow64\*,Used by App-v to get App-v server lists
verclsid.exe,c:\windows\system32\*,Used to verify a COM object before it is instantiated by Windows Explorer
verclsid.exe,c:\windows\syswow64\*,Used to verify a COM object before it is instantiated by Windows Explorer
psr.exe,c:\windows\system32\*,"Windows Problem Steps Recorder, used to record screen and clicks."
psr.exe,c:\windows\syswow64\*,"Windows Problem Steps Recorder, used to record screen and clicks."
infdefaultinstall.exe,c:\windows\system32\*,Binary used to perform installation based on content inside inf files
infdefaultinstall.exe,c:\windows\syswow64\*,Binary used to perform installation based on content inside inf files
explorer.exe,c:\windows\*,Binary used for managing files and system components within Windows
explorer.exe,c:\windows\syswow64\*,Binary used for managing files and system components within Windows
wuauclt.exe,c:\windows\system32\*,Windows Update Client
wsreset.exe,c:\windows\system32\*,Used to reset Windows Store settings according to its manifest file
finger.exe,c:\windows\system32\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
finger.exe,c:\windows\syswow64\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
regini.exe,c:\windows\system32\*,Used to manipulate the registry
regini.exe,c:\windows\syswow64\*,Used to manipulate the registry
reg.exe,c:\windows\system32\*,Used to manipulate the registry
reg.exe,c:\windows\syswow64\*,Used to manipulate the registry
syncappvpublishingserver.exe,c:\windows\system32\*,Used by App-v to get App-v server lists
syncappvpublishingserver.exe,c:\windows\syswow64\*,Used by App-v to get App-v server lists
bitsadmin.exe,c:\windows\system32\*,Used for managing background intelligent transfer
bitsadmin.exe,c:\windows\syswow64\*,Used for managing background intelligent transfer
msiexec.exe,c:\windows\system32\*,Used by Windows to execute msi files
msiexec.exe,c:\windows\syswow64\*,Used by Windows to execute msi files
regsvcs.exe,c:\windows\system32\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
regsvcs.exe,c:\windows\syswow64\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
gpscript.exe,c:\windows\system32\*,Used by group policy to process scripts
gpscript.exe,c:\windows\syswow64\*,Used by group policy to process scripts
diskshadow.exe,c:\windows\system32\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
diskshadow.exe,c:\windows\syswow64\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
ieexec.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
ieexec.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
diantz.exe,c:\windows\system32\*,Binary that package existing files into a cabinet (.cab) file
diantz.exe,c:\windows\syswow64\*,Binary that package existing files into a cabinet (.cab) file
desktopimgdownldr.exe,c:\windows\system32\*,Windows binary used to configure lockscreen/desktop image
appinstaller.exe,c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\*,Tool used for installation of AppX/MSIX applications on Windows 10
sc.exe,c:\windows\system32\*,Used by Windows to manage services
sc.exe,c:\windows\syswow64\*,Used by Windows to manage services
replace.exe,c:\windows\system32\*,Used to replace file with another file
replace.exe,c:\windows\syswow64\*,Used to replace file with another file
schtasks.exe,c:\windows\system32\*,Schedule periodic tasks
schtasks.exe,c:\windows\syswow64\*,Schedule periodic tasks
microsoft.workflow.compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,A utility included with .NET that is capable of compiling and executing C# or VB.net code.
expand.exe,c:\windows\system32\*,Binary that expands one or more compressed files
expand.exe,c:\windows\syswow64\*,Binary that expands one or more compressed files
conhost.exe,c:\windows\system32\*,Console Window host
bash.exe,c:\windows\system32\*,File used by Windows subsystem for Linux
bash.exe,c:\windows\syswow64\*,File used by Windows subsystem for Linux
pcwrun.exe,c:\windows\system32\*,Program Compatibility Wizard
fltmc.exe,c:\windows\system32\*,Filter Manager Control Program used by Windows
wmic.exe,c:\windows\system32\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
wmic.exe,c:\windows\syswow64\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI
workfolders.exe,c:\windows\system32\*,Work Folders
settingsynchost.exe,c:\windows\system32\*,Host Process for Setting Synchronization
settingsynchost.exe,c:\windows\syswow64\*,Host Process for Setting Synchronization
pktmon.exe,c:\windows\system32\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
pktmon.exe,c:\windows\syswow64\*,Capture Network Packets on the windows 10 with October 2018 Update or later.
aspnet_compiler.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ASP.NET Compilation Tool
aspnet_compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ASP.NET Compilation Tool
cscript.exe,c:\windows\system32\*,Binary used to execute scripts in Windows
cscript.exe,c:\windows\syswow64\*,Binary used to execute scripts in Windows
installutil.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
installutil.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
installutil.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
installutil.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
netsh.exe,c:\windows\system32\*,Netsh is a Windows tool used to manipulate network interface settings.
netsh.exe,c:\windows\syswow64\*,Netsh is a Windows tool used to manipulate network interface settings.
wab.exe,c:\program files\windows mail\*,Windows address book manager
wab.exe,c:\program files (x86)\windows mail\*,Windows address book manager
dnscmd.exe,c:\windows\system32\*,A command-line interface for managing DNS servers
dnscmd.exe,c:\windows\syswow64\*,A command-line interface for managing DNS servers
at.exe,c:\windows\system32\*,Schedule periodic tasks
at.exe,c:\windows\syswow64\*,Schedule periodic tasks
pcalua.exe,c:\windows\system32\*,Program Compatibility Assistant
cmdkey.exe,c:\windows\system32\*,"creates, lists, and deletes stored user names and passwords or credentials."
cmdkey.exe,c:\windows\syswow64\*,"creates, lists, and deletes stored user names and passwords or credentials."
msconfig.exe,c:\windows\system32\*,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows"
ldifde.exe,c:\windows\system32\*,"Creates, modifies, and deletes LDAP directory objects."
ldifde.exe,c:\windows\syswow64\*,"Creates, modifies, and deletes LDAP directory objects."
esentutl.exe,c:\windows\system32\*,Binary for working with Microsoft Joint Engine Technology (JET) database
esentutl.exe,c:\windows\syswow64\*,Binary for working with Microsoft Joint Engine Technology (JET) database
hh.exe,c:\windows\*,Binary used for processing chm files in Windows
hh.exe,c:\windows\syswow64\*,Binary used for processing chm files in Windows
findstr.exe,c:\windows\system32\*,"Write to ADS, discover, or download files with Findstr.exe"
findstr.exe,c:\windows\syswow64\*,"Write to ADS, discover, or download files with Findstr.exe"
verclsid.exe,c:\windows\system32\*,Used to verify a COM object before it is instantiated by Windows Explorer
verclsid.exe,c:\windows\syswow64\*,Used to verify a COM object before it is instantiated by Windows Explorer
certreq.exe,c:\windows\system32\*,Used for requesting and managing certificates
certreq.exe,c:\windows\syswow64\*,Used for requesting and managing certificates
csc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile C# code
csc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile C# code
imewdbld.exe,c:\windows\system32\ime\shared\*,Microsoft IME Open Extended Dictionary Module
presentationhost.exe,c:\windows\system32\*,File is used for executing Browser applications
presentationhost.exe,c:\windows\syswow64\*,File is used for executing Browser applications
shell32.dll,c:\windows\system32\*,Windows Shell Common Dll
shell32.dll,c:\windows\syswow64\*,Windows Shell Common Dll
zipfldr.dll,c:\windows\system32\*,Compressed Folder library
zipfldr.dll,c:\windows\syswow64\*,Compressed Folder library
desk.cpl,c:\windows\system32\*,Desktop Settings Control Panel
desk.cpl,c:\windows\syswow64\*,Desktop Settings Control Panel
comsvcs.dll,c:\windows\system32\*,COM+ Services
setupapi.dll,c:\windows\system32\*,Windows Setup Application Programming Interface
setupapi.dll,c:\windows\syswow64\*,Windows Setup Application Programming Interface
mshtml.dll,c:\windows\system32\*,Microsoft HTML Viewer
mshtml.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
advpack.dll,c:\windows\system32\*,Utility for installing software and drivers with rundll32.exe
advpack.dll,c:\windows\syswow64\*,Utility for installing software and drivers with rundll32.exe
pcwutl.dll,c:\windows\system32\*,Microsoft HTML Viewer
pcwutl.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
shdocvw.dll,c:\windows\system32\*,Shell Doc Object and Control Library.
shdocvw.dll,c:\windows\syswow64\*,Shell Doc Object and Control Library.
ieframe.dll,c:\windows\system32\*,Internet Browser DLL for translating HTML code.
ieframe.dll,c:\windows\syswow64\*,Internet Browser DLL for translating HTML code.
dfshim.dll,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfshim.dll,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET
dfshim.dll,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET
dfshim.dll,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET
pcwutl.dll,c:\windows\system32\*,Microsoft HTML Viewer
pcwutl.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
url.dll,c:\windows\system32\*,Internet Shortcut Shell Extension DLL.
url.dll,c:\windows\syswow64\*,Internet Shortcut Shell Extension DLL.
zipfldr.dll,c:\windows\system32\*,Compressed Folder library
zipfldr.dll,c:\windows\syswow64\*,Compressed Folder library
ieadvpack.dll,c:\windows\system32\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
ieadvpack.dll,c:\windows\syswow64\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
ieframe.dll,c:\windows\system32\*,Internet Browser DLL for translating HTML code.
ieframe.dll,c:\windows\syswow64\*,Internet Browser DLL for translating HTML code.
advpack.dll,c:\windows\system32\*,Utility for installing software and drivers with rundll32.exe
advpack.dll,c:\windows\syswow64\*,Utility for installing software and drivers with rundll32.exe
syssetup.dll,c:\windows\system32\*,Windows NT System Setup
syssetup.dll,c:\windows\syswow64\*,Windows NT System Setup
shell32.dll,c:\windows\system32\*,Windows Shell Common Dll
shell32.dll,c:\windows\syswow64\*,Windows Shell Common Dll
setupapi.dll,c:\windows\system32\*,Windows Setup Application Programming Interface
setupapi.dll,c:\windows\syswow64\*,Windows Setup Application Programming Interface
shdocvw.dll,c:\windows\system32\*,Shell Doc Object and Control Library.
shdocvw.dll,c:\windows\syswow64\*,Shell Doc Object and Control Library.
desk.cpl,c:\windows\system32\*,Desktop Settings Control Panel
desk.cpl,c:\windows\syswow64\*,Desktop Settings Control Panel
mshtml.dll,c:\windows\system32\*,Microsoft HTML Viewer
mshtml.dll,c:\windows\syswow64\*,Microsoft HTML Viewer
comsvcs.dll,c:\windows\system32\*,COM+ Services
cl_invocation.ps1,c:\windows\diagnostics\system\aero\*,Aero diagnostics script
cl_invocation.ps1,c:\windows\diagnostics\system\audio\*,Aero diagnostics script
cl_invocation.ps1,c:\windows\diagnostics\system\windowsupdate\*,Aero diagnostics script
winrm.vbs,c:\windows\system32\*,Script used for manage Windows RM settings
winrm.vbs,c:\windows\syswow64\*,Script used for manage Windows RM settings
manage-bde.wsf,c:\windows\system32\*,Script for managing BitLocker
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\windowsupdate\*,Proxy execution with CL_Mutexverifiers.ps1
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\audio\*,Proxy execution with CL_Mutexverifiers.ps1
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\video\*,Proxy execution with CL_Mutexverifiers.ps1
cl_mutexverifiers.ps1,c:\windows\diagnostics\system\speech\*,Proxy execution with CL_Mutexverifiers.ps1
utilityfunctions.ps1,c:\windows\diagnostics\system\networking\*,PowerShell Diagnostic Script
syncappvpublishingserver.vbs,c:\windows\system32\*,Script used related to app-v and publishing server
pester.bat,c:\program files\windowspowershell\modules\pester\3.4.0\bin\*,Used as part of the Powershell pester
pester.bat,c:\program files\windowspowershell\modules\pester\*\bin\*,Used as part of the Powershell pester
manage-bde.wsf,c:\windows\system32\*,Script for managing BitLocker
cl_loadassembly.ps1,c:\windows\diagnostics\system\audio\*,PowerShell Diagnostic Script
pubprn.vbs,c:\windows\system32\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs
pubprn.vbs,c:\windows\syswow64\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs
mftrace.exe,c:\program files (x86)\windows kits\10\bin\10.0.16299.0\*,Trace log generation tool for Media Foundation Tools.
mftrace.exe,c:\program files (x86)\windows kits\10\bin\*,Trace log generation tool for Media Foundation Tools.
dotnet.exe,c:\program files\dotnet\*,dotnet.exe comes with .NET Framework
createdump.exe,c:\program files\dotnet\shared\microsoft.netcore.app\*\*,Microsoft .NET Runtime Crash Dump Generator (included in .NET Core)
vsiisexelauncher.exe,c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\*,Binary will execute specified binary. Part of VS/VScode installation.
sqltoolsps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
dxcap.exe,c:\windows\system32\*,DirectX diagnostics/debugger included with Visual Studio.
dxcap.exe,c:\windows\syswow64\*,DirectX diagnostics/debugger included with Visual Studio.
appvlp.exe,c:\program files\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
appvlp.exe,c:\program files (x86)\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
mspub.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Publisher
mspub.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Publisher
mspub.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Publisher
mspub.exe,c:\program files\microsoft office\office16\*,Microsoft Publisher
mspub.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Publisher
mspub.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Publisher
mspub.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Publisher
mspub.exe,c:\program files\microsoft office\office15\*,Microsoft Publisher
mspub.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Publisher
mspub.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Publisher
mspub.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Publisher
mspub.exe,c:\program files\microsoft office\office14\*,Microsoft Publisher
pester.bat,c:\program files\windowspowershell\modules\pester\3.4.0\bin\*,Used as part of the Powershell pester
pester.bat,c:\program files\windowspowershell\modules\pester\*\bin\*,Used as part of the Powershell pester
cl_loadassembly.ps1,c:\windows\diagnostics\system\audio\*,PowerShell Diagnostic Script
syncappvpublishingserver.vbs,c:\windows\system32\*,Script used related to app-v and publishing server
cl_invocation.ps1,c:\windows\diagnostics\system\aero\*,Aero diagnostics script
cl_invocation.ps1,c:\windows\diagnostics\system\audio\*,Aero diagnostics script
cl_invocation.ps1,c:\windows\diagnostics\system\windowsupdate\*,Aero diagnostics script
utilityfunctions.ps1,c:\windows\diagnostics\system\networking\*,PowerShell Diagnostic Script
coregen.exe,c:\program files\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
coregen.exe,c:\program files (x86)\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
fsi.exe,c:\program files\dotnet\sdk\[sdk version]\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
fsi.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\arm64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\x64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
powerpnt.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary.
ntdsutil.exe,c:\windows\system32\*,Command line utility used to export Active Directory.
sqltoolsps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
dump64.exe,c:\program files (x86)\microsoft visual studio\installer\feedback\*,Memory dump tool that comes with Microsoft Visual Studio
wsl.exe,c:\windows\system32\*,Windows subsystem for Linux executable
csi.exe,c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\*,Command line interface included with Visual Studio.
csi.exe,c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\*,Command line interface included with Visual Studio.
mftrace.exe,c:\program files (x86)\windows kits\10\bin\10.0.16299.0\*,Trace log generation tool for Media Foundation Tools.
mftrace.exe,c:\program files (x86)\windows kits\10\bin\*,Trace log generation tool for Media Foundation Tools.
adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools
adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools
excel.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary
@@ -456,9 +421,44 @@ excel.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office bi
excel.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary
excel.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary
excel.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary
dotnet.exe,c:\program files\dotnet\*,dotnet.exe comes with .NET Framework
sqlps.exe,c:\program files (x86)\microsoft sql server\100\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\110\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\120\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\150\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\*,Verifies UI accessibility requirements
powerpnt.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary.
powerpnt.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary.
powerpnt.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary.
sqldumper.exe,c:\program files\microsoft sql server\90\shared\*,Debugging utility included with Microsoft SQL.
sqldumper.exe,c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\*,Debugging utility included with Microsoft SQL.
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools
appvlp.exe,c:\program files\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
appvlp.exe,c:\program files (x86)\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016
agentexecutor.exe,c:\program files (x86)\*,Intune Management Extension included on Intune Managed Devices
dxcap.exe,c:\windows\system32\*,DirectX diagnostics/debugger included with Visual Studio.
dxcap.exe,c:\windows\syswow64\*,DirectX diagnostics/debugger included with Visual Studio.
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools.
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools.
defaultpack.exe,c:\program files (x86)\microsoft\defaultpack\*,This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
devtoolslauncher.exe,c:\windows\system32\*,Binary will execute specified binary. Part of VS/VScode installation.
wsl.exe,c:\windows\system32\*,Windows subsystem for Linux executable
vsjitdebugger.exe,c:\windows\system32\*,Just-In-Time (JIT) debugger included with Visual Studio
vsiisexelauncher.exe,c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\*,Binary will execute specified binary. Part of VS/VScode installation.
winword.exe,c:\program files\microsoft office\root\office16\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary
@@ -474,53 +474,7 @@ winword.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office
winword.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary
winword.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary
winword.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary
agentexecutor.exe,c:\program files (x86)\*,Intune Management Extension included on Intune Managed Devices
fsi.exe,c:\program files\dotnet\sdk\[sdk version]\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
fsi.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
sqlps.exe,c:\program files (x86)\microsoft sql server\100\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\110\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\120\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
sqlps.exe,c:\program files (x86)\microsoft sql server\150\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons."
wfc.exe,c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\*,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
msohtmed.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office component
msohtmed.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office component
msohtmed.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office component
msohtmed.exe,c:\program files\microsoft office\office16\*,Microsoft Office component
msohtmed.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office component
msohtmed.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office component
msohtmed.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office component
msohtmed.exe,c:\program files\microsoft office\office15\*,Microsoft Office component
msohtmed.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office component
msohtmed.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office component
msohtmed.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office component
msohtmed.exe,c:\program files\microsoft office\office14\*,Microsoft Office component
msohtmed.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office component
msohtmed.exe,c:\program files\microsoft office\office12\*,Microsoft Office component
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools
remote.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools
fsianycpu.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,32/64-bit FSharp (F#) Interpreter included with Visual Studio.
defaultpack.exe,c:\program files (x86)\microsoft\defaultpack\*,This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
vsjitdebugger.exe,c:\windows\system32\*,Just-In-Time (JIT) debugger included with Visual Studio
wfc.exe,c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\*,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
msdeploy.exe,c:\program files (x86)\iis\microsoft web deploy v3\*,Microsoft tool used to deploy Web Applications.
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\*,Verifies UI accessibility requirements
acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\*,Verifies UI accessibility requirements
sqldumper.exe,c:\program files\microsoft sql server\90\shared\*,Debugging utility included with Microsoft SQL.
sqldumper.exe,c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\*,Debugging utility included with Microsoft SQL.
dump64.exe,c:\program files (x86)\microsoft visual studio\installer\feedback\*,Memory dump tool that comes with Microsoft Visual Studio
protocolhandler.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary
protocolhandler.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary
protocolhandler.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary
protocolhandler.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary
protocolhandler.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary
protocolhandler.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary
protocolhandler.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary
protocolhandler.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary
coregen.exe,c:\program files\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
coregen.exe,c:\program files (x86)\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight."
ntdsutil.exe,c:\windows\system32\*,Command line utility used to export Active Directory.
csi.exe,c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\*,Command line interface included with Visual Studio.
csi.exe,c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\*,Command line interface included with Visual Studio.
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools.
cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools.
1 lolbas_file_name lolbas_file_path description
2 regsvcs.exe eventvwr.exe c:\windows\system32\* Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies Displays Windows Event Logs in a GUI window.
3 regsvcs.exe eventvwr.exe c:\windows\syswow64\* Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies Displays Windows Event Logs in a GUI window.
ftp.exe c:\windows\system32\* A binary designed for connecting to FTP servers
ftp.exe c:\windows\syswow64\* A binary designed for connecting to FTP servers
dfsvc.exe c:\windows\microsoft.net\framework\v2.0.50727\* ClickOnce engine in Windows used by .NET
dfsvc.exe c:\windows\microsoft.net\framework64\v2.0.50727\* ClickOnce engine in Windows used by .NET
dfsvc.exe c:\windows\microsoft.net\framework\v4.0.30319\* ClickOnce engine in Windows used by .NET
dfsvc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* ClickOnce engine in Windows used by .NET
offlinescannershell.exe c:\program files\windows defender\offline\* Windows Defender Offline Shell
4 rasautou.exe c:\windows\system32\* Windows Remote Access Dialer
5 schtasks.exe regedit.exe c:\windows\system32\* Schedule periodic tasks Used by Windows to manipulate registry
6 schtasks.exe regedit.exe c:\windows\syswow64\* Schedule periodic tasks Used by Windows to manipulate registry
7 certreq.exe regsvr32.exe c:\windows\system32\* Used for requesting and managing certificates Used by Windows to register dlls
8 certreq.exe regsvr32.exe c:\windows\syswow64\* Used for requesting and managing certificates Used by Windows to register dlls
pktmon.exe c:\windows\system32\* Capture Network Packets on the windows 10 with October 2018 Update or later.
pktmon.exe c:\windows\syswow64\* Capture Network Packets on the windows 10 with October 2018 Update or later.
unregmp2.exe c:\windows\system32\* Microsoft Windows Media Player Setup Utility
unregmp2.exe c:\windows\syswow64\* Microsoft Windows Media Player Setup Utility
wlrmdr.exe c:\windows\system32\* Windows Logon Reminder executable
xwizard.exe c:\windows\system32\* Execute custom class that has been added to the registry or download a file with Xwizard.exe
xwizard.exe c:\windows\syswow64\* Execute custom class that has been added to the registry or download a file with Xwizard.exe
findstr.exe c:\windows\system32\* Write to ADS, discover, or download files with Findstr.exe
findstr.exe c:\windows\syswow64\* Write to ADS, discover, or download files with Findstr.exe
esentutl.exe c:\windows\system32\* Binary for working with Microsoft Joint Engine Technology (JET) database
esentutl.exe c:\windows\syswow64\* Binary for working with Microsoft Joint Engine Technology (JET) database
cscript.exe c:\windows\system32\* Binary used to execute scripts in Windows
cscript.exe c:\windows\syswow64\* Binary used to execute scripts in Windows
reg.exe c:\windows\system32\* Used to manipulate the registry
reg.exe c:\windows\syswow64\* Used to manipulate the registry
imewdbld.exe c:\windows\system32\ime\shared\* Microsoft IME Open Extended Dictionary Module
csc.exe c:\windows\microsoft.net\framework\v4.0.30319\* Binary file used by .NET to compile C# code
csc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Binary file used by .NET to compile C# code
pnputil.exe c:\windows\system32\* Used for installing drivers
atbroker.exe c:\windows\system32\* Helper binary for Assistive Technology (AT)
atbroker.exe c:\windows\syswow64\* Helper binary for Assistive Technology (AT)
datasvcutil.exe c:\windows\microsoft.net\framework64\v3.5\* DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
appinstaller.exe c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\* Tool used for installation of AppX/MSIX applications on Windows 10
print.exe c:\windows\system32\* Used by Windows to send files to the printer
print.exe c:\windows\syswow64\* Used by Windows to send files to the printer
winget.exe c:\users\user\appdata\local\microsoft\windowsapps\* Windows Package Manager tool
pcwrun.exe c:\windows\system32\* Program Compatibility Wizard
vbc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Binary file used for compile vbs code
vbc.exe c:\windows\microsoft.net\framework64\v3.5\* Binary file used for compile vbs code
diantz.exe c:\windows\system32\* Binary that package existing files into a cabinet (.cab) file
diantz.exe c:\windows\syswow64\* Binary that package existing files into a cabinet (.cab) file
rpcping.exe c:\windows\system32\* Used to verify rpc connection
rpcping.exe c:\windows\syswow64\* Used to verify rpc connection
wsreset.exe c:\windows\system32\* Used to reset Windows Store settings according to its manifest file
ttdinject.exe c:\windows\system32\* Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
ttdinject.exe c:\windows\syswow64\* Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
ilasm.exe c:\windows\microsoft.net\framework\v4.0.30319\* used for compile c# code into dll or exe.
ilasm.exe c:\windows\microsoft.net\framework64\v4.0.30319\* used for compile c# code into dll or exe.
rdrleakdiag.exe c:\windows\system32\* Microsoft Windows resource leak diagnostic tool
rdrleakdiag.exe c:\windows\syswow64\* Microsoft Windows resource leak diagnostic tool
certutil.exe c:\windows\system32\* Windows binary used for handling certificates
certutil.exe c:\windows\syswow64\* Windows binary used for handling certificates
replace.exe c:\windows\system32\* Used to replace file with another file
replace.exe c:\windows\syswow64\* Used to replace file with another file
mshta.exe c:\windows\system32\* Used by Windows to execute html applications. (.hta)
mshta.exe c:\windows\syswow64\* Used by Windows to execute html applications. (.hta)
bitsadmin.exe c:\windows\system32\* Used for managing background intelligent transfer
bitsadmin.exe c:\windows\syswow64\* Used for managing background intelligent transfer
wscript.exe c:\windows\system32\* Used by Windows to execute scripts
wscript.exe c:\windows\syswow64\* Used by Windows to execute scripts
certoc.exe c:\windows\system32\* Used for installing certificates
certoc.exe c:\windows\syswow64\* Used for installing certificates
ssh.exe c:\windows\system32\openssh\* Ssh.exe is the OpenSSH compatible client can be used to connect to Windows 10 (build 1809 and later) and Windows Server 2019 devices.
ieexec.exe c:\windows\microsoft.net\framework\v2.0.50727\* The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
ieexec.exe c:\windows\microsoft.net\framework64\v2.0.50727\* The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
cmd.exe c:\windows\system32\* The command-line interpreter in Windows
cmd.exe c:\windows\syswow64\* The command-line interpreter in Windows
microsoft.workflow.compiler.exe c:\windows\microsoft.net\framework64\v4.0.30319\* A utility included with .NET that is capable of compiling and executing C# or VB.net code.
cmdl32.exe c:\windows\system32\* Microsoft Connection Manager Auto-Download
cmdl32.exe c:\windows\syswow64\* Microsoft Connection Manager Auto-Download
runscripthelper.exe c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\* Execute target PowerShell script
runscripthelper.exe c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\* Execute target PowerShell script
printbrm.exe c:\windows\system32\spool\tools\* Printer Migration Command-Line Tool
makecab.exe c:\windows\system32\* Binary to package existing files into a cabinet (.cab) file
makecab.exe c:\windows\syswow64\* Binary to package existing files into a cabinet (.cab) file
customshellhost.exe c:\windows\system32\* A host process that is used by custom shells when using Windows in Kiosk mode.
forfiles.exe c:\windows\system32\* Selects and executes a command on a file or set of files. This command is useful for batch processing.
forfiles.exe c:\windows\syswow64\* Selects and executes a command on a file or set of files. This command is useful for batch processing.
devicecredentialdeployment.exe c:\windows\system32\* Device Credential Deployment
desktopimgdownldr.exe c:\windows\system32\* Windows binary used to configure lockscreen/desktop image
aspnet_compiler.exe c:\windows\microsoft.net\framework\v4.0.30319\* ASP.NET Compilation Tool
aspnet_compiler.exe c:\windows\microsoft.net\framework64\v4.0.30319\* ASP.NET Compilation Tool
9 control.exe c:\windows\system32\* Binary used to launch controlpanel items in Windows
10 control.exe c:\windows\syswow64\* Binary used to launch controlpanel items in Windows
11 configsecuritypolicy.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
12 scriptrunner.exe c:\windows\system32\* Execute binary through proxy binary to evade defensive counter measures
13 scriptrunner.exe c:\windows\syswow64\* Execute binary through proxy binary to evade defensive counter measures
14 offlinescannershell.exe c:\program files\windows defender\offline\* Windows Defender Offline Shell
15 atbroker.exe c:\windows\system32\* Helper binary for Assistive Technology (AT)
16 atbroker.exe c:\windows\syswow64\* Helper binary for Assistive Technology (AT)
17 mmc.exe c:\windows\system32\* Load snap-ins to locally and remotely manage Windows systems
18 mmc.exe c:\windows\syswow64\* Load snap-ins to locally and remotely manage Windows systems
19 mavinject.exe c:\windows\system32\* Used by App-v in Windows
20 mavinject.exe c:\windows\syswow64\* Used by App-v in Windows
21 ftp.exe c:\windows\system32\* A binary designed for connecting to FTP servers
22 ftp.exe c:\windows\syswow64\* A binary designed for connecting to FTP servers
23 ttdinject.exe c:\windows\system32\* Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
24 ttdinject.exe c:\windows\syswow64\* Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
25 certoc.exe c:\windows\system32\* Used for installing certificates
26 certoc.exe c:\windows\syswow64\* Used for installing certificates
27 at.exe c:\windows\system32\* Schedule periodic tasks
28 at.exe c:\windows\syswow64\* Schedule periodic tasks
29 netsh.exe c:\windows\system32\* Netsh is a Windows tool used to manipulate network interface settings.
30 netsh.exe c:\windows\syswow64\* Netsh is a Windows tool used to manipulate network interface settings.
31 pnputil.exe c:\windows\system32\* Used for installing drivers
32 ie4uinit.exe c:\windows\system32\* Executes commands from a specially prepared ie4uinit.inf file.
33 ie4uinit.exe c:\windows\syswow64\* Executes commands from a specially prepared ie4uinit.inf file.
34 infdefaultinstall.exe c:\windows\system32\* Binary used to perform installation based on content inside inf files
35 infdefaultinstall.exe c:\windows\syswow64\* Binary used to perform installation based on content inside inf files
36 forfiles.exe c:\windows\system32\* Selects and executes a command on a file or set of files. This command is useful for batch processing.
37 forfiles.exe c:\windows\syswow64\* Selects and executes a command on a file or set of files. This command is useful for batch processing.
38 register-cimprovider.exe c:\windows\system32\* Used to register new wmi providers
39 register-cimprovider.exe c:\windows\syswow64\* Used to register new wmi providers
40 tttracer.exe c:\windows\system32\* Used by Windows 1809 and newer to Debug Time Travel
41 tttracer.exe c:\windows\syswow64\* Used by Windows 1809 and newer to Debug Time Travel
42 xwizard.exe c:\windows\system32\* Execute custom class that has been added to the registry or download a file with Xwizard.exe
43 xwizard.exe c:\windows\syswow64\* Execute custom class that has been added to the registry or download a file with Xwizard.exe
44 pcalua.exe c:\windows\system32\* Program Compatibility Assistant
45 print.exe c:\windows\system32\* Used by Windows to send files to the printer
46 print.exe c:\windows\syswow64\* Used by Windows to send files to the printer
47 runscripthelper.exe c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\* Execute target PowerShell script
48 runscripthelper.exe c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\* Execute target PowerShell script
49 regasm.exe c:\windows\microsoft.net\framework\v2.0.50727\* Part of .NET
50 regasm.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Part of .NET
51 regasm.exe c:\windows\microsoft.net\framework\v4.0.30319\* Part of .NET
52 regasm.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Part of .NET
53 cmd.exe c:\windows\system32\* The command-line interpreter in Windows
54 cmd.exe c:\windows\syswow64\* The command-line interpreter in Windows
55 msbuild.exe c:\windows\microsoft.net\framework\v2.0.50727\* Used to compile and execute code
56 msbuild.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Used to compile and execute code
57 msbuild.exe c:\windows\microsoft.net\framework\v3.5\* Used to compile and execute code
59 msbuild.exe c:\windows\microsoft.net\framework\v4.0.30319\* Used to compile and execute code
60 msbuild.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Used to compile and execute code
61 msbuild.exe c:\program files (x86)\msbuild\14.0\bin\* Used to compile and execute code
62 register-cimprovider.exe certutil.exe c:\windows\system32\* Used to register new wmi providers Windows binary used for handling certificates
63 register-cimprovider.exe certutil.exe c:\windows\syswow64\* Used to register new wmi providers Windows binary used for handling certificates
64 fltmc.exe vbc.exe c:\windows\system32\* c:\windows\microsoft.net\framework64\v4.0.30319\* Filter Manager Control Program used by Windows Binary file used for compile vbs code
65 tttracer.exe vbc.exe c:\windows\system32\* c:\windows\microsoft.net\framework64\v3.5\* Used by Windows 1809 and newer to Debug Time Travel Binary file used for compile vbs code
66 tttracer.exe psr.exe c:\windows\syswow64\* c:\windows\system32\* Used by Windows 1809 and newer to Debug Time Travel Windows Problem Steps Recorder, used to record screen and clicks.
67 ie4uinit.exe psr.exe c:\windows\system32\* c:\windows\syswow64\* Executes commands from a specially prepared ie4uinit.inf file. Windows Problem Steps Recorder, used to record screen and clicks.
ie4uinit.exe c:\windows\syswow64\* Executes commands from a specially prepared ie4uinit.inf file.
fsutil.exe c:\windows\system32\* File System Utility
fsutil.exe c:\windows\syswow64\* File System Utility
sc.exe c:\windows\system32\* Used by Windows to manage services
sc.exe c:\windows\syswow64\* Used by Windows to manage services
conhost.exe c:\windows\system32\* Console Window host
bash.exe c:\windows\system32\* File used by Windows subsystem for Linux
bash.exe c:\windows\syswow64\* File used by Windows subsystem for Linux
hh.exe c:\windows\* Binary used for processing chm files in Windows
hh.exe c:\windows\syswow64\* Binary used for processing chm files in Windows
settingsynchost.exe c:\windows\system32\* Host Process for Setting Synchronization
settingsynchost.exe c:\windows\syswow64\* Host Process for Setting Synchronization
finger.exe c:\windows\system32\* Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
finger.exe c:\windows\syswow64\* Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
cmstp.exe c:\windows\system32\* Installs or removes a Connection Manager service profile.
cmstp.exe c:\windows\syswow64\* Installs or removes a Connection Manager service profile.
mmc.exe c:\windows\system32\* Load snap-ins to locally and remotely manage Windows systems
mmc.exe c:\windows\syswow64\* Load snap-ins to locally and remotely manage Windows systems
jsc.exe c:\windows\microsoft.net\framework\v4.0.30319\* Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe c:\windows\microsoft.net\framework\v2.0.50727\* Binary file used by .NET to compile javascript code to .exe or .dll format
jsc.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Binary file used by .NET to compile javascript code to .exe or .dll format
configsecuritypolicy.exe c:\program files\windows defender\* Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
configsecuritypolicy.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
stordiag.exe c:\windows\system32\* Storage diagnostic tool
stordiag.exe c:\windows\syswow64\* Storage diagnostic tool
scriptrunner.exe c:\windows\system32\* Execute binary through proxy binary to evade defensive counter measures
scriptrunner.exe c:\windows\syswow64\* Execute binary through proxy binary to evade defensive counter measures
odbcconf.exe c:\windows\system32\* Used in Windows for managing ODBC connections
odbcconf.exe c:\windows\syswow64\* Used in Windows for managing ODBC connections
68 extexport.exe c:\program files\internet explorer\* Load a DLL located in the c:\test folder with a specific name.
69 extexport.exe c:\program files (x86)\internet explorer\* Load a DLL located in the c:\test folder with a specific name.
70 rpcping.exe c:\windows\system32\* Used to verify rpc connection
71 rpcping.exe c:\windows\syswow64\* Used to verify rpc connection
72 msdt.exe c:\windows\system32\* Microsoft diagnostics tool
73 msdt.exe c:\windows\syswow64\* Microsoft diagnostics tool
workfolders.exe c:\windows\system32\* Work Folders
diskshadow.exe c:\windows\system32\* Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
diskshadow.exe c:\windows\syswow64\* Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
extrac32.exe c:\windows\system32\* Extract to ADS, copy or overwrite a file with Extrac32.exe
extrac32.exe c:\windows\syswow64\* Extract to ADS, copy or overwrite a file with Extrac32.exe
eventvwr.exe c:\windows\system32\* Displays Windows Event Logs in a GUI window.
eventvwr.exe c:\windows\syswow64\* Displays Windows Event Logs in a GUI window.
mavinject.exe c:\windows\system32\* Used by App-v in Windows
mavinject.exe c:\windows\syswow64\* Used by App-v in Windows
regasm.exe c:\windows\microsoft.net\framework\v2.0.50727\* Part of .NET
regasm.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Part of .NET
regasm.exe c:\windows\microsoft.net\framework\v4.0.30319\* Part of .NET
regasm.exe c:\windows\microsoft.net\framework64\v4.0.30319\* Part of .NET
gpscript.exe c:\windows\system32\* Used by group policy to process scripts
gpscript.exe c:\windows\syswow64\* Used by group policy to process scripts
rundll32.exe c:\windows\system32\* Used by Windows to execute dll files
rundll32.exe c:\windows\syswow64\* Used by Windows to execute dll files
regsvr32.exe c:\windows\system32\* Used by Windows to register dlls
regsvr32.exe c:\windows\syswow64\* Used by Windows to register dlls
regedit.exe c:\windows\system32\* Used by Windows to manipulate registry
regedit.exe c:\windows\syswow64\* Used by Windows to manipulate registry
msiexec.exe c:\windows\system32\* Used by Windows to execute msi files
msiexec.exe c:\windows\syswow64\* Used by Windows to execute msi files
74 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\64kb6472.inf_amd64_3daef03bbe98572b\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
75 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_0e9c57ae3396e055\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
76 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_209bd95d56b1ac2d\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
227 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132574.inf_amd64_54c9b905b975ee55\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
228 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\ki132869.inf_amd64_052eb72d070df60f\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
229 gfxdownloadwrapper.exe c:\windows\system32\driverstore\filerepository\kit126731.inf_amd64_1905c9d5f38631d9\* Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
230 wuauclt.exe dnscmd.exe c:\windows\system32\* Windows Update Client A command-line interface for managing DNS servers
231 presentationhost.exe dnscmd.exe c:\windows\system32\* c:\windows\syswow64\* File is used for executing Browser applications A command-line interface for managing DNS servers
232 presentationhost.exe wab.exe c:\windows\syswow64\* c:\program files\windows mail\* File is used for executing Browser applications Windows address book manager
233 regini.exe wab.exe c:\windows\system32\* c:\program files (x86)\windows mail\* Used to manipulate the registry Windows address book manager
234 regini.exe msconfig.exe c:\windows\syswow64\* c:\windows\system32\* Used to manipulate the registry MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows
235 wscript.exe c:\windows\system32\* Used by Windows to execute scripts
236 wscript.exe c:\windows\syswow64\* Used by Windows to execute scripts
237 makecab.exe c:\windows\system32\* Binary to package existing files into a cabinet (.cab) file
238 makecab.exe c:\windows\syswow64\* Binary to package existing files into a cabinet (.cab) file
239 datasvcutil.exe c:\windows\microsoft.net\framework64\v3.5\* DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
240 cmdl32.exe c:\windows\system32\* Microsoft Connection Manager Auto-Download
241 cmdl32.exe c:\windows\syswow64\* Microsoft Connection Manager Auto-Download
242 mshta.exe c:\windows\system32\* Used by Windows to execute html applications. (.hta)
243 mshta.exe c:\windows\syswow64\* Used by Windows to execute html applications. (.hta)
244 cmdkey.exe c:\windows\system32\* creates, lists, and deletes stored user names and passwords or credentials.
245 cmdkey.exe c:\windows\syswow64\* creates, lists, and deletes stored user names and passwords or credentials.
246 ilasm.exe c:\windows\microsoft.net\framework\v4.0.30319\* used for compile c# code into dll or exe.
247 ilasm.exe c:\windows\microsoft.net\framework64\v4.0.30319\* used for compile c# code into dll or exe.
248 rdrleakdiag.exe c:\windows\system32\* Microsoft Windows resource leak diagnostic tool
249 rdrleakdiag.exe c:\windows\syswow64\* Microsoft Windows resource leak diagnostic tool
250 mpcmdrun.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.4-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender
251 mpcmdrun.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.7-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender
252 mpcmdrun.exe c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\* Binary part of Windows Defender. Used to manage settings in Windows Defender
253 wmic.exe jsc.exe c:\windows\system32\wbem\* c:\windows\microsoft.net\framework\v4.0.30319\* The WMI command-line (WMIC) utility provides a command-line interface for WMI Binary file used by .NET to compile javascript code to .exe or .dll format
254 wmic.exe jsc.exe c:\windows\syswow64\wbem\* c:\windows\microsoft.net\framework64\v4.0.30319\* The WMI command-line (WMIC) utility provides a command-line interface for WMI Binary file used by .NET to compile javascript code to .exe or .dll format
255 jsc.exe c:\windows\microsoft.net\framework\v2.0.50727\* Binary file used by .NET to compile javascript code to .exe or .dll format
256 jsc.exe c:\windows\microsoft.net\framework64\v2.0.50727\* Binary file used by .NET to compile javascript code to .exe or .dll format
257 cmstp.exe c:\windows\system32\* Installs or removes a Connection Manager service profile.
258 cmstp.exe c:\windows\syswow64\* Installs or removes a Connection Manager service profile.
259 stordiag.exe c:\windows\system32\* Storage diagnostic tool
260 stordiag.exe c:\windows\syswow64\* Storage diagnostic tool
261 odbcconf.exe c:\windows\system32\* Used in Windows for managing ODBC connections
262 odbcconf.exe c:\windows\syswow64\* Used in Windows for managing ODBC connections
263 wlrmdr.exe c:\windows\system32\* Windows Logon Reminder executable
264 printbrm.exe c:\windows\system32\spool\tools\* Printer Migration Command-Line Tool
265 dfsvc.exe c:\windows\microsoft.net\framework\v2.0.50727\* ClickOnce engine in Windows used by .NET
266 dfsvc.exe c:\windows\microsoft.net\framework64\v2.0.50727\* ClickOnce engine in Windows used by .NET
267 dfsvc.exe c:\windows\microsoft.net\framework\v4.0.30319\* ClickOnce engine in Windows used by .NET
268 dfsvc.exe c:\windows\microsoft.net\framework64\v4.0.30319\* ClickOnce engine in Windows used by .NET
269 extrac32.exe c:\windows\system32\* Extract to ADS, copy or overwrite a file with Extrac32.exe
270 extrac32.exe c:\windows\syswow64\* Extract to ADS, copy or overwrite a file with Extrac32.exe
271 rundll32.exe c:\windows\system32\* Used by Windows to execute dll files
272 rundll32.exe c:\windows\syswow64\* Used by Windows to execute dll files
273 runonce.exe c:\windows\system32\* Executes a Run Once Task that has been configured in the registry
274 runonce.exe c:\windows\syswow64\* Executes a Run Once Task that has been configured in the registry
syncappvpublishingserver.exe c:\windows\system32\* Used by App-v to get App-v server lists
syncappvpublishingserver.exe c:\windows\syswow64\* Used by App-v to get App-v server lists
verclsid.exe c:\windows\system32\* Used to verify a COM object before it is instantiated by Windows Explorer
verclsid.exe c:\windows\syswow64\* Used to verify a COM object before it is instantiated by Windows Explorer
psr.exe c:\windows\system32\* Windows Problem Steps Recorder, used to record screen and clicks.
psr.exe c:\windows\syswow64\* Windows Problem Steps Recorder, used to record screen and clicks.
infdefaultinstall.exe c:\windows\system32\* Binary used to perform installation based on content inside inf files
infdefaultinstall.exe c:\windows\syswow64\* Binary used to perform installation based on content inside inf files
275 explorer.exe c:\windows\* Binary used for managing files and system components within Windows
276 explorer.exe c:\windows\syswow64\* Binary used for managing files and system components within Windows
277 wuauclt.exe c:\windows\system32\* Windows Update Client
278 wsreset.exe c:\windows\system32\* Used to reset Windows Store settings according to its manifest file
279 finger.exe c:\windows\system32\* Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
280 finger.exe c:\windows\syswow64\* Displays information about a user or users on a specified remote computer that is running the Finger service or daemon
281 regini.exe c:\windows\system32\* Used to manipulate the registry
282 regini.exe c:\windows\syswow64\* Used to manipulate the registry
283 reg.exe c:\windows\system32\* Used to manipulate the registry
284 reg.exe c:\windows\syswow64\* Used to manipulate the registry
285 syncappvpublishingserver.exe c:\windows\system32\* Used by App-v to get App-v server lists
286 syncappvpublishingserver.exe c:\windows\syswow64\* Used by App-v to get App-v server lists
287 bitsadmin.exe c:\windows\system32\* Used for managing background intelligent transfer
288 bitsadmin.exe c:\windows\syswow64\* Used for managing background intelligent transfer
289 msiexec.exe c:\windows\system32\* Used by Windows to execute msi files
290 msiexec.exe c:\windows\syswow64\* Used by Windows to execute msi files
291 regsvcs.exe c:\windows\system32\* Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
292 regsvcs.exe c:\windows\syswow64\* Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
293 gpscript.exe c:\windows\system32\* Used by group policy to process scripts
294 gpscript.exe c:\windows\syswow64\* Used by group policy to process scripts
295 diskshadow.exe c:\windows\system32\* Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
296 diskshadow.exe c:\windows\syswow64\* Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
297 ieexec.exe c:\windows\microsoft.net\framework\v2.0.50727\* The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
298 ieexec.exe c:\windows\microsoft.net\framework64\v2.0.50727\* The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
299 diantz.exe c:\windows\system32\* Binary that package existing files into a cabinet (.cab) file
300 diantz.exe c:\windows\syswow64\* Binary that package existing files into a cabinet (.cab) file
301 desktopimgdownldr.exe c:\windows\system32\* Windows binary used to configure lockscreen/desktop image
302 appinstaller.exe c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\* Tool used for installation of AppX/MSIX applications on Windows 10
303 sc.exe c:\windows\system32\* Used by Windows to manage services
304 sc.exe c:\windows\syswow64\* Used by Windows to manage services
305 replace.exe c:\windows\system32\* Used to replace file with another file
306 replace.exe c:\windows\syswow64\* Used to replace file with another file
307 schtasks.exe c:\windows\system32\* Schedule periodic tasks
308 schtasks.exe c:\windows\syswow64\* Schedule periodic tasks
309 microsoft.workflow.compiler.exe c:\windows\microsoft.net\framework64\v4.0.30319\* A utility included with .NET that is capable of compiling and executing C# or VB.net code.
310 expand.exe c:\windows\system32\* Binary that expands one or more compressed files
311 expand.exe c:\windows\syswow64\* Binary that expands one or more compressed files
312 conhost.exe c:\windows\system32\* Console Window host
313 bash.exe c:\windows\system32\* File used by Windows subsystem for Linux
314 bash.exe c:\windows\syswow64\* File used by Windows subsystem for Linux
315 pcwrun.exe c:\windows\system32\* Program Compatibility Wizard
316 fltmc.exe c:\windows\system32\* Filter Manager Control Program used by Windows
317 wmic.exe c:\windows\system32\wbem\* The WMI command-line (WMIC) utility provides a command-line interface for WMI
318 wmic.exe c:\windows\syswow64\wbem\* The WMI command-line (WMIC) utility provides a command-line interface for WMI
319 workfolders.exe c:\windows\system32\* Work Folders
320 settingsynchost.exe c:\windows\system32\* Host Process for Setting Synchronization
321 settingsynchost.exe c:\windows\syswow64\* Host Process for Setting Synchronization
322 pktmon.exe c:\windows\system32\* Capture Network Packets on the windows 10 with October 2018 Update or later.
323 pktmon.exe c:\windows\syswow64\* Capture Network Packets on the windows 10 with October 2018 Update or later.
324 aspnet_compiler.exe c:\windows\microsoft.net\framework\v4.0.30319\* ASP.NET Compilation Tool
325 aspnet_compiler.exe c:\windows\microsoft.net\framework64\v4.0.30319\* ASP.NET Compilation Tool
326 cscript.exe c:\windows\system32\* Binary used to execute scripts in Windows
327 cscript.exe c:\windows\syswow64\* Binary used to execute scripts in Windows
328 installutil.exe c:\windows\microsoft.net\framework\v2.0.50727\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
329 installutil.exe c:\windows\microsoft.net\framework64\v2.0.50727\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
330 installutil.exe c:\windows\microsoft.net\framework\v4.0.30319\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
331 installutil.exe c:\windows\microsoft.net\framework64\v4.0.30319\* The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
332 netsh.exe esentutl.exe c:\windows\system32\* Netsh is a Windows tool used to manipulate network interface settings. Binary for working with Microsoft Joint Engine Technology (JET) database
333 netsh.exe esentutl.exe c:\windows\syswow64\* Netsh is a Windows tool used to manipulate network interface settings. Binary for working with Microsoft Joint Engine Technology (JET) database
334 wab.exe hh.exe c:\program files\windows mail\* c:\windows\* Windows address book manager Binary used for processing chm files in Windows
335 wab.exe hh.exe c:\program files (x86)\windows mail\* c:\windows\syswow64\* Windows address book manager Binary used for processing chm files in Windows
336 dnscmd.exe findstr.exe c:\windows\system32\* A command-line interface for managing DNS servers Write to ADS, discover, or download files with Findstr.exe
337 dnscmd.exe findstr.exe c:\windows\syswow64\* A command-line interface for managing DNS servers Write to ADS, discover, or download files with Findstr.exe
338 at.exe verclsid.exe c:\windows\system32\* Schedule periodic tasks Used to verify a COM object before it is instantiated by Windows Explorer
339 at.exe verclsid.exe c:\windows\syswow64\* Schedule periodic tasks Used to verify a COM object before it is instantiated by Windows Explorer
340 pcalua.exe certreq.exe c:\windows\system32\* Program Compatibility Assistant Used for requesting and managing certificates
341 cmdkey.exe certreq.exe c:\windows\system32\* c:\windows\syswow64\* creates, lists, and deletes stored user names and passwords or credentials. Used for requesting and managing certificates
342 cmdkey.exe csc.exe c:\windows\syswow64\* c:\windows\microsoft.net\framework\v4.0.30319\* creates, lists, and deletes stored user names and passwords or credentials. Binary file used by .NET to compile C# code
343 msconfig.exe csc.exe c:\windows\system32\* c:\windows\microsoft.net\framework64\v4.0.30319\* MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows Binary file used by .NET to compile C# code
344 ldifde.exe imewdbld.exe c:\windows\system32\* c:\windows\system32\ime\shared\* Creates, modifies, and deletes LDAP directory objects. Microsoft IME Open Extended Dictionary Module
345 ldifde.exe presentationhost.exe c:\windows\syswow64\* c:\windows\system32\* Creates, modifies, and deletes LDAP directory objects. File is used for executing Browser applications
346 presentationhost.exe c:\windows\syswow64\* File is used for executing Browser applications
347 shell32.dll c:\windows\system32\* Windows Shell Common Dll
348 shell32.dll c:\windows\syswow64\* Windows Shell Common Dll
349 zipfldr.dll c:\windows\system32\* Compressed Folder library
350 zipfldr.dll c:\windows\syswow64\* Compressed Folder library
351 desk.cpl c:\windows\system32\* Desktop Settings Control Panel
352 desk.cpl c:\windows\syswow64\* Desktop Settings Control Panel
353 comsvcs.dll c:\windows\system32\* COM+ Services
354 setupapi.dll c:\windows\system32\* Windows Setup Application Programming Interface
355 setupapi.dll c:\windows\syswow64\* Windows Setup Application Programming Interface
356 mshtml.dll c:\windows\system32\* Microsoft HTML Viewer
357 mshtml.dll c:\windows\syswow64\* Microsoft HTML Viewer
358 advpack.dll c:\windows\system32\* Utility for installing software and drivers with rundll32.exe
359 advpack.dll c:\windows\syswow64\* Utility for installing software and drivers with rundll32.exe
360 pcwutl.dll c:\windows\system32\* Microsoft HTML Viewer
361 pcwutl.dll c:\windows\syswow64\* Microsoft HTML Viewer
362 shdocvw.dll c:\windows\system32\* Shell Doc Object and Control Library.
363 shdocvw.dll c:\windows\syswow64\* Shell Doc Object and Control Library.
364 ieframe.dll c:\windows\system32\* Internet Browser DLL for translating HTML code.
365 ieframe.dll c:\windows\syswow64\* Internet Browser DLL for translating HTML code.
366 dfshim.dll c:\windows\microsoft.net\framework\v2.0.50727\* ClickOnce engine in Windows used by .NET
367 dfshim.dll c:\windows\microsoft.net\framework64\v2.0.50727\* ClickOnce engine in Windows used by .NET
368 dfshim.dll c:\windows\microsoft.net\framework\v4.0.30319\* ClickOnce engine in Windows used by .NET
369 dfshim.dll c:\windows\microsoft.net\framework64\v4.0.30319\* ClickOnce engine in Windows used by .NET
pcwutl.dll c:\windows\system32\* Microsoft HTML Viewer
pcwutl.dll c:\windows\syswow64\* Microsoft HTML Viewer
370 url.dll c:\windows\system32\* Internet Shortcut Shell Extension DLL.
371 url.dll c:\windows\syswow64\* Internet Shortcut Shell Extension DLL.
zipfldr.dll c:\windows\system32\* Compressed Folder library
zipfldr.dll c:\windows\syswow64\* Compressed Folder library
372 ieadvpack.dll c:\windows\system32\* INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
373 ieadvpack.dll c:\windows\syswow64\* INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
ieframe.dll c:\windows\system32\* Internet Browser DLL for translating HTML code.
ieframe.dll c:\windows\syswow64\* Internet Browser DLL for translating HTML code.
advpack.dll c:\windows\system32\* Utility for installing software and drivers with rundll32.exe
advpack.dll c:\windows\syswow64\* Utility for installing software and drivers with rundll32.exe
374 syssetup.dll c:\windows\system32\* Windows NT System Setup
375 syssetup.dll c:\windows\syswow64\* Windows NT System Setup
shell32.dll c:\windows\system32\* Windows Shell Common Dll
shell32.dll c:\windows\syswow64\* Windows Shell Common Dll
setupapi.dll c:\windows\system32\* Windows Setup Application Programming Interface
setupapi.dll c:\windows\syswow64\* Windows Setup Application Programming Interface
shdocvw.dll c:\windows\system32\* Shell Doc Object and Control Library.
shdocvw.dll c:\windows\syswow64\* Shell Doc Object and Control Library.
desk.cpl c:\windows\system32\* Desktop Settings Control Panel
desk.cpl c:\windows\syswow64\* Desktop Settings Control Panel
mshtml.dll c:\windows\system32\* Microsoft HTML Viewer
mshtml.dll c:\windows\syswow64\* Microsoft HTML Viewer
comsvcs.dll c:\windows\system32\* COM+ Services
cl_invocation.ps1 c:\windows\diagnostics\system\aero\* Aero diagnostics script
cl_invocation.ps1 c:\windows\diagnostics\system\audio\* Aero diagnostics script
cl_invocation.ps1 c:\windows\diagnostics\system\windowsupdate\* Aero diagnostics script
376 winrm.vbs c:\windows\system32\* Script used for manage Windows RM settings
377 winrm.vbs c:\windows\syswow64\* Script used for manage Windows RM settings
378 manage-bde.wsf c:\windows\system32\* Script for managing BitLocker
379 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\windowsupdate\* Proxy execution with CL_Mutexverifiers.ps1
380 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\audio\* Proxy execution with CL_Mutexverifiers.ps1
381 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\video\* Proxy execution with CL_Mutexverifiers.ps1
382 cl_mutexverifiers.ps1 c:\windows\diagnostics\system\speech\* Proxy execution with CL_Mutexverifiers.ps1
utilityfunctions.ps1 c:\windows\diagnostics\system\networking\* PowerShell Diagnostic Script
syncappvpublishingserver.vbs c:\windows\system32\* Script used related to app-v and publishing server
pester.bat c:\program files\windowspowershell\modules\pester\3.4.0\bin\* Used as part of the Powershell pester
pester.bat c:\program files\windowspowershell\modules\pester\*\bin\* Used as part of the Powershell pester
manage-bde.wsf c:\windows\system32\* Script for managing BitLocker
cl_loadassembly.ps1 c:\windows\diagnostics\system\audio\* PowerShell Diagnostic Script
383 pubprn.vbs c:\windows\system32\printing_admin_scripts\en-us\* Proxy execution with Pubprn.vbs
384 pubprn.vbs c:\windows\syswow64\printing_admin_scripts\en-us\* Proxy execution with Pubprn.vbs
385 mftrace.exe pester.bat c:\program files (x86)\windows kits\10\bin\10.0.16299.0\* c:\program files\windowspowershell\modules\pester\3.4.0\bin\* Trace log generation tool for Media Foundation Tools. Used as part of the Powershell pester
386 mftrace.exe pester.bat c:\program files (x86)\windows kits\10\bin\* c:\program files\windowspowershell\modules\pester\*\bin\* Trace log generation tool for Media Foundation Tools. Used as part of the Powershell pester
387 dotnet.exe cl_loadassembly.ps1 c:\program files\dotnet\* c:\windows\diagnostics\system\audio\* dotnet.exe comes with .NET Framework PowerShell Diagnostic Script
388 createdump.exe syncappvpublishingserver.vbs c:\program files\dotnet\shared\microsoft.netcore.app\*\* c:\windows\system32\* Microsoft .NET Runtime Crash Dump Generator (included in .NET Core) Script used related to app-v and publishing server
389 vsiisexelauncher.exe cl_invocation.ps1 c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\* c:\windows\diagnostics\system\aero\* Binary will execute specified binary. Part of VS/VScode installation. Aero diagnostics script
390 sqltoolsps.exe cl_invocation.ps1 c:\program files (x86)\microsoft sql server\130\tools\binn\* c:\windows\diagnostics\system\audio\* Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+. Aero diagnostics script
391 dxcap.exe cl_invocation.ps1 c:\windows\system32\* c:\windows\diagnostics\system\windowsupdate\* DirectX diagnostics/debugger included with Visual Studio. Aero diagnostics script
392 dxcap.exe utilityfunctions.ps1 c:\windows\syswow64\* c:\windows\diagnostics\system\networking\* DirectX diagnostics/debugger included with Visual Studio. PowerShell Diagnostic Script
393 appvlp.exe coregen.exe c:\program files\microsoft office\root\client\* c:\program files\microsoft silverlight\5.1.50918.0\* Application Virtualization Utility Included with Microsoft Office 2016 Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
394 appvlp.exe coregen.exe c:\program files (x86)\microsoft office\root\client\* c:\program files (x86)\microsoft silverlight\5.1.50918.0\* Application Virtualization Utility Included with Microsoft Office 2016 Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
395 mspub.exe fsi.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* c:\program files\dotnet\sdk\[sdk version]\fsharp\* Microsoft Publisher 64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
396 mspub.exe fsi.exe c:\program files\microsoft office 16\clientx64\root\office16\* c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\* Microsoft Publisher 64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
mspub.exe c:\program files (x86)\microsoft office\office16\* Microsoft Publisher
mspub.exe c:\program files\microsoft office\office16\* Microsoft Publisher
mspub.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* Microsoft Publisher
mspub.exe c:\program files\microsoft office 15\clientx64\root\office15\* Microsoft Publisher
mspub.exe c:\program files (x86)\microsoft office\office15\* Microsoft Publisher
mspub.exe c:\program files\microsoft office\office15\* Microsoft Publisher
mspub.exe c:\program files (x86)\microsoft office 14\clientx86\root\office14\* Microsoft Publisher
mspub.exe c:\program files\microsoft office 14\clientx64\root\office14\* Microsoft Publisher
mspub.exe c:\program files (x86)\microsoft office\office14\* Microsoft Publisher
mspub.exe c:\program files\microsoft office\office14\* Microsoft Publisher
397 visualuiaverifynative.exe c:\program files (x86)\windows kits\10\bin\[sdk version]\arm64\uiaverify\* A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
398 visualuiaverifynative.exe c:\program files (x86)\windows kits\10\bin\[sdk version]\x64\uiaverify\* A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
399 visualuiaverifynative.exe c:\program files (x86)\windows kits\10\bin\[sdk version]\uiaverify\* A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
400 powerpnt.exe ntdsutil.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* c:\windows\system32\* Microsoft Office binary. Command line utility used to export Active Directory.
401 powerpnt.exe sqltoolsps.exe c:\program files\microsoft office 16\clientx64\root\office16\* c:\program files (x86)\microsoft sql server\130\tools\binn\* Microsoft Office binary. Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
402 powerpnt.exe dump64.exe c:\program files (x86)\microsoft office\office16\* c:\program files (x86)\microsoft visual studio\installer\feedback\* Microsoft Office binary. Memory dump tool that comes with Microsoft Visual Studio
403 powerpnt.exe wsl.exe c:\program files\microsoft office\office16\* c:\windows\system32\* Microsoft Office binary. Windows subsystem for Linux executable
404 powerpnt.exe csi.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\* Microsoft Office binary. Command line interface included with Visual Studio.
405 powerpnt.exe csi.exe c:\program files\microsoft office 15\clientx64\root\office15\* c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\* Microsoft Office binary. Command line interface included with Visual Studio.
406 powerpnt.exe mftrace.exe c:\program files (x86)\microsoft office\office15\* c:\program files (x86)\windows kits\10\bin\10.0.16299.0\* Microsoft Office binary. Trace log generation tool for Media Foundation Tools.
407 powerpnt.exe mftrace.exe c:\program files\microsoft office\office15\* c:\program files (x86)\windows kits\10\bin\* Microsoft Office binary. Trace log generation tool for Media Foundation Tools.
powerpnt.exe c:\program files (x86)\microsoft office 14\clientx86\root\office14\* Microsoft Office binary.
powerpnt.exe c:\program files\microsoft office 14\clientx64\root\office14\* Microsoft Office binary.
powerpnt.exe c:\program files (x86)\microsoft office\office14\* Microsoft Office binary.
powerpnt.exe c:\program files\microsoft office\office14\* Microsoft Office binary.
powerpnt.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office binary.
powerpnt.exe c:\program files\microsoft office\office12\* Microsoft Office binary.
408 adplus.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools
409 adplus.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools
410 excel.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office binary
421 excel.exe c:\program files\microsoft office\office14\* Microsoft Office binary
422 excel.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office binary
423 excel.exe c:\program files\microsoft office\office12\* Microsoft Office binary
424 dotnet.exe c:\program files\dotnet\* dotnet.exe comes with .NET Framework
425 sqlps.exe c:\program files (x86)\microsoft sql server\100\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
426 sqlps.exe c:\program files (x86)\microsoft sql server\110\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
427 sqlps.exe c:\program files (x86)\microsoft sql server\120\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
428 sqlps.exe c:\program files (x86)\microsoft sql server\130\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
429 sqlps.exe c:\program files (x86)\microsoft sql server\150\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
430 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\* Verifies UI accessibility requirements
431 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\* Verifies UI accessibility requirements
432 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\* Verifies UI accessibility requirements
433 acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\* Verifies UI accessibility requirements
434 powerpnt.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office binary.
435 powerpnt.exe c:\program files\microsoft office 16\clientx64\root\office16\* Microsoft Office binary.
436 powerpnt.exe c:\program files (x86)\microsoft office\office16\* Microsoft Office binary.
437 powerpnt.exe c:\program files\microsoft office\office16\* Microsoft Office binary.
438 powerpnt.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* Microsoft Office binary.
439 powerpnt.exe c:\program files\microsoft office 15\clientx64\root\office15\* Microsoft Office binary.
440 powerpnt.exe c:\program files (x86)\microsoft office\office15\* Microsoft Office binary.
441 powerpnt.exe c:\program files\microsoft office\office15\* Microsoft Office binary.
442 powerpnt.exe c:\program files (x86)\microsoft office 14\clientx86\root\office14\* Microsoft Office binary.
443 powerpnt.exe c:\program files\microsoft office 14\clientx64\root\office14\* Microsoft Office binary.
444 powerpnt.exe c:\program files (x86)\microsoft office\office14\* Microsoft Office binary.
445 powerpnt.exe c:\program files\microsoft office\office14\* Microsoft Office binary.
446 powerpnt.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office binary.
447 powerpnt.exe c:\program files\microsoft office\office12\* Microsoft Office binary.
448 sqldumper.exe c:\program files\microsoft sql server\90\shared\* Debugging utility included with Microsoft SQL.
449 sqldumper.exe c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\* Debugging utility included with Microsoft SQL.
450 remote.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools
451 remote.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools
452 appvlp.exe c:\program files\microsoft office\root\client\* Application Virtualization Utility Included with Microsoft Office 2016
453 appvlp.exe c:\program files (x86)\microsoft office\root\client\* Application Virtualization Utility Included with Microsoft Office 2016
454 agentexecutor.exe c:\program files (x86)\* Intune Management Extension included on Intune Managed Devices
455 dxcap.exe c:\windows\system32\* DirectX diagnostics/debugger included with Visual Studio.
456 dxcap.exe c:\windows\syswow64\* DirectX diagnostics/debugger included with Visual Studio.
457 cdb.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools.
458 cdb.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools.
459 defaultpack.exe c:\program files (x86)\microsoft\defaultpack\* This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
460 devtoolslauncher.exe c:\windows\system32\* Binary will execute specified binary. Part of VS/VScode installation.
461 wsl.exe vsiisexelauncher.exe c:\windows\system32\* c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\* Windows subsystem for Linux executable Binary will execute specified binary. Part of VS/VScode installation.
vsjitdebugger.exe c:\windows\system32\* Just-In-Time (JIT) debugger included with Visual Studio
462 winword.exe c:\program files\microsoft office\root\office16\* Microsoft Office binary
463 winword.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office binary
464 winword.exe c:\program files\microsoft office 16\clientx64\root\office16\* Microsoft Office binary
474 winword.exe c:\program files\microsoft office\office14\* Microsoft Office binary
475 winword.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office binary
476 winword.exe c:\program files\microsoft office\office12\* Microsoft Office binary
agentexecutor.exe c:\program files (x86)\* Intune Management Extension included on Intune Managed Devices
fsi.exe c:\program files\dotnet\sdk\[sdk version]\fsharp\* 64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
fsi.exe c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\* 64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
sqlps.exe c:\program files (x86)\microsoft sql server\100\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
sqlps.exe c:\program files (x86)\microsoft sql server\110\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
sqlps.exe c:\program files (x86)\microsoft sql server\120\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
sqlps.exe c:\program files (x86)\microsoft sql server\130\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
sqlps.exe c:\program files (x86)\microsoft sql server\150\tools\binn\* Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
wfc.exe c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\* The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
msohtmed.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office component
msohtmed.exe c:\program files\microsoft office 16\clientx64\root\office16\* Microsoft Office component
msohtmed.exe c:\program files (x86)\microsoft office\office16\* Microsoft Office component
msohtmed.exe c:\program files\microsoft office\office16\* Microsoft Office component
msohtmed.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* Microsoft Office component
msohtmed.exe c:\program files\microsoft office 15\clientx64\root\office15\* Microsoft Office component
msohtmed.exe c:\program files (x86)\microsoft office\office15\* Microsoft Office component
msohtmed.exe c:\program files\microsoft office\office15\* Microsoft Office component
msohtmed.exe c:\program files (x86)\microsoft office 14\clientx86\root\office14\* Microsoft Office component
msohtmed.exe c:\program files\microsoft office 14\clientx64\root\office14\* Microsoft Office component
msohtmed.exe c:\program files (x86)\microsoft office\office14\* Microsoft Office component
msohtmed.exe c:\program files\microsoft office\office14\* Microsoft Office component
msohtmed.exe c:\program files (x86)\microsoft office\office12\* Microsoft Office component
msohtmed.exe c:\program files\microsoft office\office12\* Microsoft Office component
remote.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools
remote.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools
477 fsianycpu.exe c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\* 32/64-bit FSharp (F#) Interpreter included with Visual Studio.
478 defaultpack.exe vsjitdebugger.exe c:\program files (x86)\microsoft\defaultpack\* c:\windows\system32\* This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider. Just-In-Time (JIT) debugger included with Visual Studio
479 wfc.exe c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\* The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
480 msdeploy.exe c:\program files (x86)\iis\microsoft web deploy v3\* Microsoft tool used to deploy Web Applications.
acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\* Verifies UI accessibility requirements
acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\* Verifies UI accessibility requirements
acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\* Verifies UI accessibility requirements
acccheckconsole.exe c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\* Verifies UI accessibility requirements
sqldumper.exe c:\program files\microsoft sql server\90\shared\* Debugging utility included with Microsoft SQL.
sqldumper.exe c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\* Debugging utility included with Microsoft SQL.
dump64.exe c:\program files (x86)\microsoft visual studio\installer\feedback\* Memory dump tool that comes with Microsoft Visual Studio
protocolhandler.exe c:\program files (x86)\microsoft office 16\clientx86\root\office16\* Microsoft Office binary
protocolhandler.exe c:\program files\microsoft office 16\clientx64\root\office16\* Microsoft Office binary
protocolhandler.exe c:\program files (x86)\microsoft office\office16\* Microsoft Office binary
protocolhandler.exe c:\program files\microsoft office\office16\* Microsoft Office binary
protocolhandler.exe c:\program files (x86)\microsoft office 15\clientx86\root\office15\* Microsoft Office binary
protocolhandler.exe c:\program files\microsoft office 15\clientx64\root\office15\* Microsoft Office binary
protocolhandler.exe c:\program files (x86)\microsoft office\office15\* Microsoft Office binary
protocolhandler.exe c:\program files\microsoft office\office15\* Microsoft Office binary
coregen.exe c:\program files\microsoft silverlight\5.1.50918.0\* Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
coregen.exe c:\program files (x86)\microsoft silverlight\5.1.50918.0\* Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
ntdsutil.exe c:\windows\system32\* Command line utility used to export Active Directory.
csi.exe c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\* Command line interface included with Visual Studio.
csi.exe c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\* Command line interface included with Visual Studio.
cdb.exe c:\program files (x86)\windows kits\10\debuggers\x64\* Debugging tool included with Windows Debugging Tools.
cdb.exe c:\program files (x86)\windows kits\10\debuggers\x86\* Debugging tool included with Windows Debugging Tools.
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard Path
id: a8289f22-2df9-4d67-9913-de8fc0954d02
id: c842931e-661f-42bc-a4df-0460d93cfb69
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path
id: 32134938-37d4-4ec5-8714-46ca49769d20
id: ecaaf956-c516-4980-b08e-8c01c19614ca
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path
id: 56061a68-08af-4d8a-b0c3-e3e4477d2264
id: 3284e4f4-67f7-49b6-ad5e-a8fcead2eef8
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path
id: 0327b45f-3531-4efc-9b51-46e716eb454a
id: e124f71f-11bc-47e4-9931-6046d256005d
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path
id: 0f97913c-5aa4-443d-b111-676da584db6e
id: 057c06c7-ef31-4749-b5c9-199152e53a06
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path
id: da9de3e2-66ab-43ec-bbc8-4875d2115fec
id: 93862a89-abe0-4094-909a-08ec390aa5e3
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard Path
id: 41218a31-e6b8-4ea3-88dc-d588e1b45a5f
id: d75cc561-3828-4d0a-92c4-0eb93bfe0929
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
+2 -2
View File
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path
id: 51fd491e-b38a-4657-b5c8-7f6410b9bbcf
id: 6401d583-0052-4dc5-a713-68b510826d2b
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path
id: 09d6531d-b55b-4d46-8e7a-9b455563fd03
id: b8da7ea5-8c16-4eff-9787-54ec271159e0
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Bash exe LOLBAS in Non Standard Path
id: d47efd9c-2e31-4d38-ab95-c7db6908106b
id: 57bb8624-26b3-4d23-a35c-17d5b2fa03b2
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Bitsadmin exe LOLBAS in Non Standard Path
id: 69e7e9bb-e08e-4972-9140-9adb08ebe199
id: 919cfed5-71e3-4b56-8468-bfa0f8e48763
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cdb exe LOLBAS in Non Standard Path
id: 4f0445e8-3d5a-470b-925c-b76f3eff60ee
id: 438a17bb-ffad-4540-a92b-c82177b6c584
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Certoc exe LOLBAS in Non Standard Path
id: 6e8f20ff-265a-46b8-9681-e8442178b09c
id: 46e1d51f-2979-42e4-8397-63abb398fe71
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Certreq exe LOLBAS in Non Standard Path
id: 6c0ab09e-2be3-4fd0-b887-60240a68fb16
id: 3b322498-f89c-4407-a43d-3218f5debbc5
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Certutil exe LOLBAS in Non Standard Path
id: 8402b60f-0a97-4d58-a927-bc4b1b04112c
id: 9de4a1d7-65bf-4a6f-b25f-c926570c6543
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cl_invocation ps1 LOLBAS in Non Standard Path
id: 49630b63-7407-4a0b-b9c1-13741db4a2e4
id: b84023f7-4fc9-429e-bb10-ab19095041f1
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cl_loadassembly ps1 LOLBAS in Non Standard Path
id: 80dae1e3-ed8e-4abf-b62b-b322d4d7eb3b
id: a32d2585-a516-4808-a130-92f480c55988
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Cl_mutexverifiers ps1 LOLBAS in Non Standard
Path
id: 4a98b0d1-88c0-4234-8d2a-44cbfe7f70b6
id: 53c3b8a2-9e6c-4b34-8bf3-c76fd4fcacf3
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cmd exe LOLBAS in Non Standard Path
id: eddf68bb-7442-465f-aca6-d6be8c029781
id: 90784ffc-3576-45d7-bb16-d62f6120c4e5
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cmdkey exe LOLBAS in Non Standard Path
id: 3a46ac20-f603-40e3-a4f3-a77aded3305b
id: 304b4002-dfad-422e-93b7-bb6e9a490513
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cmdl32 exe LOLBAS in Non Standard Path
id: f9ea7424-1805-4b7c-828e-97564b96a08d
id: 10de5e76-a676-4149-a949-1132b117a11a
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cmstp exe LOLBAS in Non Standard Path
id: f473e060-a390-4567-9a4d-99cbde81da79
id: c7cb13df-b234-4654-86c6-9a35c930de42
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Comsvcs dll LOLBAS in Non Standard Path
id: 8035fb1d-f610-4b54-9d1e-dcaca3ca06af
id: 3b4d71e9-ceb0-48ea-b1c1-a62dd66b9f66
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Configsecuritypolicy exe LOLBAS in Non Standard
Path
id: 28427e48-405d-4d0d-8bb5-851dbe3a14f2
id: 2212344c-5a19-4907-b561-b91832c54fa8
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Conhost exe LOLBAS in Non Standard Path
id: 18c2d6d3-8712-49d2-b3ff-3950131ce8da
id: d1c99845-9762-4da4-b30e-7fbf05304baf
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Control exe LOLBAS in Non Standard Path
id: de93877e-1926-4a57-93c7-ccc9110177ad
id: 8f4b0432-e5cd-434e-a87d-bffa2e936adb
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Coregen exe LOLBAS in Non Standard Path
id: 3557c88c-e036-47b2-9516-cad111189568
id: 5964991e-0c6e-4fb1-b9f3-acae15fd9858
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Csc exe LOLBAS in Non Standard Path
id: acfeacea-5688-4f5a-b71a-572eccb9ea0b
id: ea783c88-d20f-461b-a295-cf1a87bd8502
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Cscript exe LOLBAS in Non Standard Path
id: afe8315c-ada9-4156-b26c-f64e7bcc6644
id: dfcc58d1-4f59-42a6-85f9-7ea2085ae8fe
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Csi exe LOLBAS in Non Standard Path
id: d72eb4a1-d1bd-430e-ac81-54b85e62706b
id: 5258b32a-b811-4323-9e98-4701b8a6295c
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Datasvcutil exe LOLBAS in Non Standard Path
id: 83f76c3f-8f26-4e75-9841-706b93550561
id: cf1686f6-516f-4e58-ae86-524e162def2f
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Defaultpack exe LOLBAS in Non Standard Path
id: 1f0f4073-a44b-4d0a-831c-8678ad0ba107
id: 640aa341-73f5-4958-8d44-7d4171af8862
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Desk cpl LOLBAS in Non Standard Path
id: e6b350d8-a238-4a31-8521-1353c9639aa0
id: 7f6caf3f-0f0f-4c3e-ba8b-04664bc12771
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Desktopimgdownldr exe LOLBAS in Non Standard
Path
id: 3a77606b-d07b-4aff-8901-8337b72b1597
id: c9f3d074-f077-4d98-9eec-f9e3629e5e58
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Devtoolslauncher exe LOLBAS in Non Standard
Path
id: c502882c-44ab-4556-ba3c-c9bec806ff3f
id: 989eef3d-36d4-4b83-a004-94f7f171e529
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Dfshim dll LOLBAS in Non Standard Path
id: 31d997d3-d28b-4bd5-b368-066fe410c699
id: 2615f2e9-0f34-4106-b649-7a5ff5644f9f
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Dfsvc exe LOLBAS in Non Standard Path
id: 91272b91-c17a-4be7-a85e-6fae80ef124a
id: 0bf3fa5b-e25a-476b-8474-61ad82e4d82c
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Diantz exe LOLBAS in Non Standard Path
id: 118c96e6-f3bf-4217-a2ee-9eba800eb91d
id: 09bcd983-9735-45e7-9bdd-a78f4557954d
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Diskshadow exe LOLBAS in Non Standard Path
id: 3c2a10c5-bb47-49f8-bc2e-1894291e2526
id: 38ce0449-88f2-47c6-b6bd-0619f674a33d
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Dnscmd exe LOLBAS in Non Standard Path
id: ccdf5719-a825-4a66-8276-b6ef5c74cc3d
id: 9972c51f-0b1e-4dff-8341-678520c4ddf8
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Dotnet exe LOLBAS in Non Standard Path
id: 5ec76143-7216-4fdc-a4cc-3c9d6a7568ea
id: 083ee82a-4880-4561-b781-6aded01e73f1
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Dump64 exe LOLBAS in Non Standard Path
id: 76ffd818-0875-4a66-af22-f5593839b518
id: c9742210-66ea-4ed1-a3c0-575bfa2ca17a
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Dxcap exe LOLBAS in Non Standard Path
id: 200434f5-1166-4a81-ae29-b9896a2d0ad7
id: 5078946b-8127-4250-8eab-8d57e3d7f098
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Esentutl exe LOLBAS in Non Standard Path
id: 91324284-cad8-4f47-a740-749f12aafe55
id: 3ca5f24f-44ef-466b-a5c6-6cdc873b0691
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Eventvwr exe LOLBAS in Non Standard Path
id: 3510501d-efb0-4757-8f89-d36e803d32ba
id: a59816c5-c95a-4695-b9f9-654d7b36ebfb
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Excel exe LOLBAS in Non Standard Path
id: c4a66592-3896-47e6-8727-7a769c171a2e
id: 3cb8bfea-8c07-4f69-8761-98700d3150e9
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Expand exe LOLBAS in Non Standard Path
id: 6a93a1f4-4506-43ad-a235-10df7ac68827
id: 1c8ccd46-9837-49b5-979e-f857d7d9ef03
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Explorer exe LOLBAS in Non Standard Path
id: 1ffa5de9-97a8-4f22-af89-5f574a328207
id: 1b95b89f-16cf-4cb6-b027-3a98c3bbfd9d
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Extexport exe LOLBAS in Non Standard Path
id: fb84ddd5-5736-4f41-8479-74484a45f050
id: 6271e582-73b7-4eaa-8293-37cb70bf5082
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Extrac32 exe LOLBAS in Non Standard Path
id: 3e302ff2-d2c6-4a70-b9e0-3f4b4dead4e6
id: 88e5cd66-11c0-49ca-ad84-e8207f2995fc
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Findstr exe LOLBAS in Non Standard Path
id: f516a212-56ea-463e-bdf0-292699098d86
id: a46647a3-97e4-40fb-84b0-09d5e3b00ad0
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Finger exe LOLBAS in Non Standard Path
id: b16dc603-5b05-4d67-81b8-d609edfa5cdf
id: 1d59e315-3933-4dba-8ada-dc7adc2043d4
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Fltmc exe LOLBAS in Non Standard Path
id: 84024943-d316-4992-9b0b-1e7cfd1f0524
id: 3a47909d-b5b8-4ff2-83d6-04976fe889dd
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Forfiles exe LOLBAS in Non Standard Path
id: 5189854a-6766-45a3-8fd5-cc06c476f878
id: 51687bfe-5c7a-4fbc-8a4a-4ae0322e2add
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Fsi exe LOLBAS in Non Standard Path
id: 40596539-81b1-43aa-85f1-6bb7bee45930
id: 10219cc2-89a3-4566-b682-d7e01b6bdfb6
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Fsianycpu exe LOLBAS in Non Standard Path
id: 3ea3b7e3-ac4b-4c9e-b605-d7b3ef6091cb
id: c1c3eeaa-90a6-4ae7-b48d-1ae233a515fe
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Ftp exe LOLBAS in Non Standard Path
id: 083d3948-85f8-4460-a613-afa5aa89c81a
id: 589f706c-bc5f-4fdd-9d48-c70c599236b5
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Gfxdownloadwrapper exe LOLBAS in Non Standard
Path
id: 7ef96cdf-d856-4ebc-8937-702d41158d79
id: 3ed5ff81-7f18-4bf5-b6a9-38cf256d6217
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Gpscript exe LOLBAS in Non Standard Path
id: 8dee5018-e8c5-4cbe-a031-7bd5e76de467
id: 09326d45-46bd-4f26-8158-1b73b26e2c24
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
+2 -2
View File
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Hh exe LOLBAS in Non Standard Path
id: f9a6eccb-a77c-4322-9263-cb587438f0ec
id: 1aa89968-690e-483d-8d76-1dd214185741
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Ie4uinit exe LOLBAS in Non Standard Path
id: 8e47e7fd-616a-49b8-b97d-3132f18cff02
id: 09e2fffa-ad65-40ed-afff-433b80b4bd07
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Ieadvpack dll LOLBAS in Non Standard Path
id: befc38d7-5566-4b7a-aed3-7e77cda85a90
id: ce1a96d5-64b3-465f-a300-e6d720157219
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Ieexec exe LOLBAS in Non Standard Path
id: 9c442fca-d43f-4419-b9f7-e86706902e3d
id: 2e2c29d5-5f4b-4ad5-91b2-1c8d41b77277
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Ieframe dll LOLBAS in Non Standard Path
id: deb510e0-d338-499a-9333-ae6a92bbe1ee
id: 1a45dbdf-97f4-43cd-9620-5cac48faab8d
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Ilasm exe LOLBAS in Non Standard Path
id: 754eb562-8a5a-44d5-a36d-b98304db0ddc
id: 1fbc75a1-33af-48e0-9199-e716b2bb29cc
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Imewdbld exe LOLBAS in Non Standard Path
id: 65bc00f8-acd2-4c3a-8bc9-6b70067fe179
id: d0a64b6d-7d06-4c04-99e9-04c497a94264
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Infdefaultinstall exe LOLBAS in Non Standard
Path
id: ed336a3b-3940-4fa5-b2d3-1a70255b6b7e
id: d53987d7-ae11-4032-b958-fcc434d72ff9
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Installutil exe LOLBAS in Non Standard Path
id: 3940d2f5-34b5-4568-af6d-adae72fca9dc
id: 204af1e5-1473-4686-a2d4-5d5fd2a9b232
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Jsc exe LOLBAS in Non Standard Path
id: 359b9d0d-3927-4bfd-ac25-83a47cd86c10
id: 666474aa-ed53-47bc-a6f9-fb9e59fa2e2d
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Makecab exe LOLBAS in Non Standard Path
id: 1be3fe66-eb96-40e9-ac6b-372c863411de
id: 6dee426a-b2d0-4bc7-aedc-405d0e7b1bf0
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Manage-bde wsf LOLBAS in Non Standard Path
id: 66a535f0-3de0-47a8-ad0f-351a31d1a765
id: 54c4ee98-046c-42c8-b300-fd408f66b576
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Mavinject exe LOLBAS in Non Standard Path
id: b75786ad-5306-4c7f-ad39-f1cc072c2114
id: d9bc0697-fdd6-4f96-bf7b-563f31a0e7ba
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Mftrace exe LOLBAS in Non Standard Path
id: 59b6dd12-ad92-4c23-9382-a71018dd49cd
id: 59698f8b-0dd3-4ec9-b0ed-4c277d9cd73f
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Microsoft workflow compiler exe LOLBAS in Non
Standard Path
id: d91f6bc2-dea6-4e15-9794-eae0518c9b55
id: 63fbf81a-f2a7-4ea6-98a3-54771f75d989
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Mmc exe LOLBAS in Non Standard Path
id: ea408a87-9613-4856-96ae-c87e77c2777d
id: 17e6ced3-8c95-4068-abb6-da08449c25d5
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Mpcmdrun exe LOLBAS in Non Standard Path
id: a6de19ec-7aba-43d3-a692-d2257eaaa221
id: 51639291-3360-497a-bd74-a776e6df0e2e
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Msbuild exe LOLBAS in Non Standard Path
id: cb765ec2-f449-4e26-8852-ae5a068020bc
id: d2c831e7-d40c-4457-83d7-5b0c6b31ca6c
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Msconfig exe LOLBAS in Non Standard Path
id: 0d42b215-dfd4-4f09-b6f8-cc51b94c726a
id: d35eb933-8473-4265-ad98-f5998e6f75d6
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Msdeploy exe LOLBAS in Non Standard Path
id: 942dcb56-8f11-4e26-afea-5f3c795723e2
id: 0ac4bd64-94d1-4dc7-82ce-ce2fe424cb0e
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Msdt exe LOLBAS in Non Standard Path
id: c5056ba2-6b1f-4272-a92b-2dca08a8f98a
id: 363d3d99-a83f-4108-992c-c059e93573ad
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Mshta exe LOLBAS in Non Standard Path
id: d1c46649-8b38-4b8a-9149-320c9ab7dd3f
id: 8a6ed35c-b70f-4f8f-8220-6dc93dc837a1
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Mshtml dll LOLBAS in Non Standard Path
id: 8e2051c3-8af9-408e-92f9-e1bac4dc6077
id: 716484b0-ca55-4f93-9ba8-0e7de3f354fc
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Msiexec exe LOLBAS in Non Standard Path
id: 7fb47baf-fc9d-48ff-8a11-90696b9a10e1
id: 5141dbfe-f28f-43c4-b241-58b8683f7853
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Netsh exe LOLBAS in Non Standard Path
id: 031f33d2-2885-4636-a4cd-b6a6fe486219
id: a3aa5f0b-5e64-40ce-9251-9502bc0782c5
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Ntdsutil exe LOLBAS in Non Standard Path
id: cd032dae-ec33-4e4e-8146-19c7c22354ca
id: 3083a087-c7ac-48b3-aa6e-936e8baaa9fc
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Odbcconf exe LOLBAS in Non Standard Path
id: f9071baf-f478-4b27-83ec-e12fc7b314af
id: d8420544-9e5c-4b93-b4de-8b941ff83e3d
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Offlinescannershell exe LOLBAS in Non Standard
Path
id: 347f7605-bc67-4a52-839e-9b5e459bba36
id: 3a003375-e207-41ee-987e-5aeef00cb61f
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Pcalua exe LOLBAS in Non Standard Path
id: fa7fd32d-406f-4055-9f46-e10b3b4b64b7
id: 1d50072e-23b7-4ba3-b3d7-8344cf167dcd
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Pcwrun exe LOLBAS in Non Standard Path
id: e3d1aaee-abf8-4d6e-97ac-7b170792d2bb
id: ccf2ac56-7cff-4c9e-87af-d25d66f9dd61
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Pcwutl dll LOLBAS in Non Standard Path
id: 37212469-2095-4b78-b7f5-b95147740147
id: 0757b899-ed7e-445a-b67d-c5f297846478
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Pester bat LOLBAS in Non Standard Path
id: 4a3f92cf-2e0b-4919-a9a6-21eff8f7f8a2
id: aa6db9ce-d51c-4814-b3bd-a48338355387
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Pktmon exe LOLBAS in Non Standard Path
id: d5c1e0d6-bd7e-4409-a6b6-e40f6229aa4e
id: e02cf071-cc34-4755-b39a-4f2baaa767d7
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Pnputil exe LOLBAS in Non Standard Path
id: 9d07ecc7-384a-44e4-ae7a-348d6cb548dd
id: 445364f4-92f4-48fb-8da9-4279202a90f9
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Powerpnt exe LOLBAS in Non Standard Path
id: 184e41c3-e35c-48b0-bedd-a9a0940bb624
id: 459cc44e-61a4-457a-91c2-f3c27295e2a9
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,8 +1,8 @@
name: Windows Rename System Utilities Presentationhost exe LOLBAS in Non Standard
Path
id: 9062fd96-c0c4-4c26-bb5e-62f5e9665f6f
id: 8e8b72de-1db9-4d55-b681-55f3ae32183e
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Print exe LOLBAS in Non Standard Path
id: 1b50de1e-2d7c-4748-b3f6-1c7255ad709d
id: a3720c97-9aa4-448d-ad60-8179407e3398
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Printbrm exe LOLBAS in Non Standard Path
id: d5db0481-91d7-412f-ac48-956c9569de05
id: b3bad5a2-5ad9-49d2-8a42-cee1bd372db8
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Psr exe LOLBAS in Non Standard Path
id: b3e328d2-1f6c-4303-9c21-62bdd110dc1f
id: 537f9e80-01d8-4eca-8f43-8fbf0e29a8a9
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:
@@ -1,7 +1,7 @@
name: Windows Rename System Utilities Pubprn vbs LOLBAS in Non Standard Path
id: 40f0aa11-521b-4185-a462-c6482f5f8756
id: 7d90df95-b47a-4072-88d8-73eb0c484492
version: 1
date: '2022-10-17'
date: '2022-10-18'
author: Splunk Threat Research Bot, Splunk
type: Anomaly
datamodel:

Some files were not shown because too many files have changed in this diff Show More