ARP.EXE
Sources: 300M+ executions observed in the wild.
Summary
Windows ARP utility - displays and modifies the Address Resolution Protocol (ARP) cache, mapping IP addresses to MAC addresses.
ARP.EXE is the 795th most commonly executed Windows program in EchoTrail's dataset, observed 4,021 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by Lenovo.Modern.ImController.PluginHost.CompanionApp.exe.
Get this in your tools
The same record for arp.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/arp.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\SysWOW6497.07%
- C:\Windows\System322.93%
Top Hashes (SHA256)
- 6f928475e24f329dfd465d7b2411573b9824c317c704708e077f4732e58d015343.33%
- cebbca243dc97da5d37620298d675341663080d7428198310805fb19eb35a41a42.81%
- 700a0ca0ba2efedda6536ddf7905e658890e76b327942a4d8a6afa31a23450b210.2%
- 60f270a0e99e75851ebe6eed6df8f7d50fcf07bd34445b5518b48ad8f230af450.87%
- 7b79171410482f410b7572c58edb7fd39326f7150c7c6882249b1cf9d7c970f00.77%
- d9b84f11fdea5a621edf3ccbb6363285c9421438f35641d306d4cd841aabd65d0.62%
- ec54b37cdb3567f3a81384fc6abf9220ada8b2df6c087ade8c7e075687b09fa90.62%
- 5c95e274daa0ffc07cc1f9c9669778f8c4c8eff8497be0a8a4a0591b512639ae0.35%
- cca1f962f9435330c556f07a1745d743ad7acad7561c4c79420b0bf16c8e1d0a0.15%
- 95446d661b61c83fc3cc8952e1a5448e662d0695aaf7787db5ec0038dd3973c20.07%
Process Ancestry
Top Grandparents
- explorer.exe18.18%
- WmiPrvSE.exe1.44%
- userinit.exe0.24%
Top Parents
- cmd.exe3.66%
- explorer.exe0.02%
Top Children
- conhost.exe100%
Security Analysis
What does ARP.EXE normally do?
Used by network administrators to view and manage ARP cache entries for troubleshooting.
When is ARP.EXE suspicious?
Execution by non-admin users. Running as part of a script that also calls ipconfig, netstat, net, etc. (enumeration chain). Adding static ARP entries.
How do attackers abuse ARP.EXE?
Used for network reconnaissance to discover active hosts on the local subnet. Part of common post-exploitation enumeration scripts. "arp -a" reveals all known hosts on the network segment.
Detection guidance
Monitor for arp.exe as part of enumeration chains (arp + ipconfig + netstat + net in sequence). Single invocations are usually benign; patterned execution is suspicious.
False positive notes
Network troubleshooting by IT staff. Network monitoring scripts may periodically query ARP tables.
Related Processes
Ask Rocky about ARP.EXE
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for ARP.EXE. The free tier returns the summary, 500 lookups a month. Or ask Rocky.