ARP.EXE

by Microsoft
System Utilitymedium risk

Sources: 300M+ executions observed in the wild.

Summary

Windows ARP utility - displays and modifies the Address Resolution Protocol (ARP) cache, mapping IP addresses to MAC addresses.

ARP.EXE is the 795th most commonly executed Windows program in EchoTrail's dataset, observed 4,021 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by Lenovo.Modern.ImController.PluginHost.CompanionApp.exe.

Get this in your tools

The same record for arp.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/arp.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

795th
most commonly executed Windows program
4,021
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\SysWOW6497.07%
  • C:\Windows\System322.93%

Top Hashes (SHA256)

  • 6f928475e24f329dfd465d7b2411573b9824c317c704708e077f4732e58d015343.33%
  • cebbca243dc97da5d37620298d675341663080d7428198310805fb19eb35a41a42.81%
  • 700a0ca0ba2efedda6536ddf7905e658890e76b327942a4d8a6afa31a23450b210.2%
  • 60f270a0e99e75851ebe6eed6df8f7d50fcf07bd34445b5518b48ad8f230af450.87%
  • 7b79171410482f410b7572c58edb7fd39326f7150c7c6882249b1cf9d7c970f00.77%
  • d9b84f11fdea5a621edf3ccbb6363285c9421438f35641d306d4cd841aabd65d0.62%
  • ec54b37cdb3567f3a81384fc6abf9220ada8b2df6c087ade8c7e075687b09fa90.62%
  • 5c95e274daa0ffc07cc1f9c9669778f8c4c8eff8497be0a8a4a0591b512639ae0.35%
  • cca1f962f9435330c556f07a1745d743ad7acad7561c4c79420b0bf16c8e1d0a0.15%
  • 95446d661b61c83fc3cc8952e1a5448e662d0695aaf7787db5ec0038dd3973c20.07%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does ARP.EXE normally do?

Used by network administrators to view and manage ARP cache entries for troubleshooting.

When is ARP.EXE suspicious?

Execution by non-admin users. Running as part of a script that also calls ipconfig, netstat, net, etc. (enumeration chain). Adding static ARP entries.

How do attackers abuse ARP.EXE?

Used for network reconnaissance to discover active hosts on the local subnet. Part of common post-exploitation enumeration scripts. "arp -a" reveals all known hosts on the network segment.

Detection guidance

Monitor for arp.exe as part of enumeration chains (arp + ipconfig + netstat + net in sequence). Single invocations are usually benign; patterned execution is suspicious.

False positive notes

Network troubleshooting by IT staff. Network monitoring scripts may periodically query ARP tables.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about ARP.EXE

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for ARP.EXE. The free tier returns the summary, 500 lookups a month. Or ask Rocky.