cacheset.exe

by Sysinternals - www.sysinternals.com
System Utility

Sources: observed in the EchoTrail lab on Windows 11.

Summary

cacheset.exe (Manipulate the working-set parameters of the system file cache) is part of Sysinternals Cacheset, by Sysinternals - www.sysinternals.com.

cacheset.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-24 installed from manual_url package https://live.sysinternals.com/Cacheset.exe.

Get this in your tools

The same record for cacheset.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/cacheset.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

2687th
most commonly executed Windows program
n/a
observed endpoint executions

Behavior

Top Paths

  • C:\Program Files (x86)\IBM\Lotus\Notes100%
  • C:\lab\in

Top Hashes (SHA256)

  • 8be947d9f8d4fb8131f559976ca0b1f6a88c71531848842ba68b064dbe20aed7100%
  • 43203ae51a144e4ff92d4110c93af12b7c9525a1f5435efedfd3499dc12d16c2

Process Ancestry

Top Grandparents

Top Parents

Top Children

Lab record

Installed from
manual_url https://live.sysinternals.com/Cacheset.exe
Publisher
Microsoft Corporation
Persistence
1 service
Network
none
Command lines
1 pattern (1 launch)
DLL loads
31 patterns (32 loads)
Registry writes
0 patterns (0 writes)
File writes
0 patterns (0 writes)
HTTP requests
0 patterns (0 requests)
TLS connections
0 patterns (0 handshakes)
Named pipes
0 patterns (0 events)
Process access
0 patterns (0 events)
Driver loads
0 patterns (0 loads)
PowerShell blocks
0 patterns (0 blocks)
Remote threads
0 patterns (0 events)
Audit events
1 pattern (1 event)

Full record on Team.

Security Analysis

What does cacheset.exe normally do?

Legitimate use is an administrator or performance engineer running Cacheset.exe interactively (or with a switch such as /S to apply saved settings) to tune or reset the system file cache working set; it requires elevation and the SeIncreaseQuotaPrivilege, runs briefly, and exits. In the lab the binary was executed once as "C:\lab\in\Cacheset.exe" /S with powershell.exe as the parent, was signed by Microsoft Corporation with a valid signature, spawned no child processes, and generated no network traffic of its own. All other observed activity — MicrosoftEdgeUpdate.exe /svc, /ping, /ua and its setup chain, OneDriveSetup/FileSyncConfig/OneDrive.Sync.Service, Defender MpSigStub/MpCmdRun/wevtutil manifest re-registration, and the TLS connections to Microsoft endpoints — is routine Windows 11 background servicing unrelated to CacheSet. Typical artifacts are a Sysinternals EULA-accepted value under HKCU\Software\Sysinternals\CacheSet and, for GUI use, brief conhost/window activity.

When is cacheset.exe suspicious?

Execution from user-writable or staging paths (%TEMP%, %APPDATA%, C:\Users\Public, C:\ProgramData, or a WebDAV/UNC path such as \\live.sysinternals.com\tools\cacheset.exe) rather than an admin tools directory; the binary present under a renamed or generic filename while version info still reads "Sysinternals Cacheset"; a parent chain rooted in a browser, mail client, Office app, script host (wscript/cscript/mshta), or a remote-execution service (PsExec/PSEXESVC, WMI, WinRM, service creation) instead of an interactive admin shell; execution on servers/workstations where no performance tuning ticket exists; appearance alongside other freshly dropped Sysinternals binaries (procdump, psexec, psexesvc, pssuspend) in the same directory and minute; repeated or looped invocations that repeatedly flush the cache; first-ever appearance of the Sysinternals EULA registry key immediately before other tool executions; and downloads of Cacheset.exe from live.sysinternals.com by a non-admin process.

How do attackers abuse cacheset.exe?

CacheSet itself has little documented use in real intrusions and is not a LOLBAS entry — it cannot execute arbitrary code, load user DLLs, or proxy payloads. Its realistic abuse is as part of the broader "bring your own Sysinternals" tradecraft: adversaries and commodity loaders stage Microsoft-signed Sysinternals binaries (often pulled from live.sysinternals.com, including the WebDAV share \\live.sysinternals.com\tools, which allows running tools straight from the internet without a local drop) to blend with admin activity and satisfy allowlists, then rename them to innocuous names for masquerading. Because CacheSet repeatedly zeroes/forces the system file cache working set via NtSetSystemInformation, it can be used opportunistically as a crude resource/performance degradation or anti-forensics nuisance (forcing cached file data out of memory, adding I/O pressure) on servers, and its presence normalizes the staging directory used for genuinely offensive Sysinternals tools such as PsExec (lateral movement) and ProcDump (LSASS credential dumping). It has also been used as decoy/filler content in trojanized "admin toolkit" archives and fake utility bundles that pair a legitimate signed tool with a malicious sideloaded DLL or second-stage installer. Treat detections as ecosystem indicators — the tool arriving where it does not belong matters far more than what it does.

Detection guidance

Baseline Cacheset.exe as rare-to-absent in most environments and alert on any execution, keying on image path outside approved admin tooling directories, on UNC/WebDAV image paths, and on original-filename metadata "Cacheset" mismatching the on-disk name (Sysmon Event 1 OriginalFileName vs Image). Pivot from any hit to sibling file-creation events in the same directory (Sysmon 11) to catch a full Sysinternals bundle, and to the creating process — script hosts, Office, browsers, or remote-exec services as ancestors are the strongest abuse signal. Hunt for first-seen HKCU\Software\Sysinternals\*\EulaAccepted writes and for network retrievals of live.sysinternals.com or downloads.sysinternals.com by non-browser processes. Correlate elevated-token, non-interactive executions (no conhost/window, SYSTEM or service parent) and repeated short-interval runs, which do not fit the one-off interactive tuning baseline observed in the lab.

MITRE ATT&CK techniques

Ask Rocky about cacheset.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for cacheset.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.