adb.exe
Sources: 300M+ executions observed in the wild.
Summary
Android Debug Bridge. Command-line tool for communicating with Android devices for development and debugging.
adb.exe is the 115th most commonly executed Windows program in EchoTrail's dataset, observed 188,393 times across enterprise environments. It typically runs from C:\Program Files\Magnet Forensics\Magnet AXIOM\AXIOM Process\ADB\adb7 and it is most often launched by AXIOMProcess.exe.
Get this in your tools
The same record for adb.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/adb.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Program Files\Magnet Forensics\Magnet AXIOM\AXIOM Process\ADB\adb792.96%
- C:\Program Files\Genymobile\Genymotion\tools4.29%
- C:\Program Files (x86)\Magnet Acquire\ADB\adb72.52%
- C:\Program Files (x86)\WugFresh Development\Nexus Root Toolkit\data0.16%
- C:\Users\...0.04%
- C:\Program Files (x86)\EaseUS\Todo Backup\bin0.02%
- C:\Program Files (x86)\FonePaw\FonePaw DoTrans\adb<0.01%
- C:\Program Files (x86)\Android\android-sdk\platform-tools<0.01%
- C:\Program Files\Microvirt\MEmu<0.01%
- C:\Program Files (x86)\Magnet Acquire\ADB<0.01%
Top Hashes (SHA256)
- 28c7f9efc61632cb8437fe58de2ec8f615f8e0bba17819f05651903c0f68e9af90.9%
- bbe9ae11b27bfecd4f5f0b981cddf235e5e703572e367a931b94ecbf6cfe17aa5.28%
- b40abda76f72462483a95321caf431b752b7988de0f92bcb0ba27bf6e3b86bfc3.53%
- 46663d96f3d26040a4928a521d75d6669c9ee1ed315a32681b7a6399995da6030.19%
- a3887975396c74b6d4bdb49d2030881165e09b4ed89b0c7bbaf4b821d44d46430.05%
- 1bff6a77f984abaef62e43aef721cb5bb54a1ff08c5946eb2d6530c8df0b40430.03%
- 71489c655f1a33cd463c652798caa85725780cb8c1f93d05f13fe29de31ab1e30.01%
- 348179b6593cf255bed4f79df4f298a8d449230f596ae033e29f5d28647803b70.01%
- 259f7767bd3d218af14d82b9876276df395870b47c8548c717c6afee068a5a0c<0.01%
- c30394cfaa86ed8914e8becae2ee94bdd476d6aee6b840ed08eed379bc66f6b9<0.01%
Process Ancestry
Top Grandparents
- explorer.exe63.23%
- AXIOMProcess.exe17.15%
- wyupdate.exe0.29%
- services.exe0.09%
- cmd.exe0.04%
- unins000.exe<0.01%
Top Parents
- AXIOMProcess.exe73.23%
- adb.exe20.39%
- cmd.exe0.19%
- agent.exe0.02%
- devenv.exe<0.01%
Top Children
- conhost.exe79.57%
- adb.exe20.43%
- WerFault.exe<0.01%
Security Analysis
What does adb.exe normally do?
Part of Google (Android SDK) software.
When is adb.exe suspicious?
Running from unexpected paths.
How do attackers abuse adb.exe?
Not commonly abused.
Detection guidance
No specific detection needed.
False positive notes
Normal operation.
Ask Rocky about adb.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for adb.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.