cacheset.exe
Sources: observed in the EchoTrail lab on Windows 11.
Summary
cacheset.exe (Manipulate the working-set parameters of the system file cache) is part of Sysinternals Cacheset, by Sysinternals - www.sysinternals.com.
cacheset.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-24 installed from manual_url package https://live.sysinternals.com/Cacheset.exe.
Get this in your tools
The same record for cacheset.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/cacheset.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Program Files (x86)\IBM\Lotus\Notes100%
- C:\lab\in
Top Hashes (SHA256)
- 8be947d9f8d4fb8131f559976ca0b1f6a88c71531848842ba68b064dbe20aed7100%
- 43203ae51a144e4ff92d4110c93af12b7c9525a1f5435efedfd3499dc12d16c2
Process Ancestry
Top Grandparents
- services.exe100%
Top Parents
Top Children
- conhost.exe100%
Lab record
- Installed from
- manual_url https://live.sysinternals.com/Cacheset.exe
- Publisher
- Microsoft Corporation
- Persistence
- 1 service
- Network
- none
- Command lines
- 1 pattern (1 launch)
- DLL loads
- 31 patterns (32 loads)
- Registry writes
- 0 patterns (0 writes)
- File writes
- 0 patterns (0 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 0 patterns (0 handshakes)
- Named pipes
- 0 patterns (0 events)
- Process access
- 0 patterns (0 events)
- Driver loads
- 0 patterns (0 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 1 pattern (1 event)
Full record on Team.
Security Analysis
What does cacheset.exe normally do?
Legitimate use is an administrator or performance engineer running Cacheset.exe interactively (or with a switch such as /S to apply saved settings) to tune or reset the system file cache working set; it requires elevation and the SeIncreaseQuotaPrivilege, runs briefly, and exits. In the lab the binary was executed once as "C:\lab\in\Cacheset.exe" /S with powershell.exe as the parent, was signed by Microsoft Corporation with a valid signature, spawned no child processes, and generated no network traffic of its own. All other observed activity — MicrosoftEdgeUpdate.exe /svc, /ping, /ua and its setup chain, OneDriveSetup/FileSyncConfig/OneDrive.Sync.Service, Defender MpSigStub/MpCmdRun/wevtutil manifest re-registration, and the TLS connections to Microsoft endpoints — is routine Windows 11 background servicing unrelated to CacheSet. Typical artifacts are a Sysinternals EULA-accepted value under HKCU\Software\Sysinternals\CacheSet and, for GUI use, brief conhost/window activity.
When is cacheset.exe suspicious?
Execution from user-writable or staging paths (%TEMP%, %APPDATA%, C:\Users\Public, C:\ProgramData, or a WebDAV/UNC path such as \\live.sysinternals.com\tools\cacheset.exe) rather than an admin tools directory; the binary present under a renamed or generic filename while version info still reads "Sysinternals Cacheset"; a parent chain rooted in a browser, mail client, Office app, script host (wscript/cscript/mshta), or a remote-execution service (PsExec/PSEXESVC, WMI, WinRM, service creation) instead of an interactive admin shell; execution on servers/workstations where no performance tuning ticket exists; appearance alongside other freshly dropped Sysinternals binaries (procdump, psexec, psexesvc, pssuspend) in the same directory and minute; repeated or looped invocations that repeatedly flush the cache; first-ever appearance of the Sysinternals EULA registry key immediately before other tool executions; and downloads of Cacheset.exe from live.sysinternals.com by a non-admin process.
How do attackers abuse cacheset.exe?
CacheSet itself has little documented use in real intrusions and is not a LOLBAS entry — it cannot execute arbitrary code, load user DLLs, or proxy payloads. Its realistic abuse is as part of the broader "bring your own Sysinternals" tradecraft: adversaries and commodity loaders stage Microsoft-signed Sysinternals binaries (often pulled from live.sysinternals.com, including the WebDAV share \\live.sysinternals.com\tools, which allows running tools straight from the internet without a local drop) to blend with admin activity and satisfy allowlists, then rename them to innocuous names for masquerading. Because CacheSet repeatedly zeroes/forces the system file cache working set via NtSetSystemInformation, it can be used opportunistically as a crude resource/performance degradation or anti-forensics nuisance (forcing cached file data out of memory, adding I/O pressure) on servers, and its presence normalizes the staging directory used for genuinely offensive Sysinternals tools such as PsExec (lateral movement) and ProcDump (LSASS credential dumping). It has also been used as decoy/filler content in trojanized "admin toolkit" archives and fake utility bundles that pair a legitimate signed tool with a malicious sideloaded DLL or second-stage installer. Treat detections as ecosystem indicators — the tool arriving where it does not belong matters far more than what it does.
Detection guidance
Baseline Cacheset.exe as rare-to-absent in most environments and alert on any execution, keying on image path outside approved admin tooling directories, on UNC/WebDAV image paths, and on original-filename metadata "Cacheset" mismatching the on-disk name (Sysmon Event 1 OriginalFileName vs Image). Pivot from any hit to sibling file-creation events in the same directory (Sysmon 11) to catch a full Sysinternals bundle, and to the creating process — script hosts, Office, browsers, or remote-exec services as ancestors are the strongest abuse signal. Hunt for first-seen HKCU\Software\Sysinternals\*\EulaAccepted writes and for network retrievals of live.sysinternals.com or downloads.sysinternals.com by non-browser processes. Correlate elevated-token, non-interactive executions (no conhost/window, SYSTEM or service parent) and repeated short-interval runs, which do not fit the one-off interactive tuning baseline observed in the lab.
Ask Rocky about cacheset.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for cacheset.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.