elevation_service.exe

by Google/Microsoft
Web Browser

Sources: 300M+ executions observed in the wild and observed in the EchoTrail lab on Windows 11.

Summary

Browser Elevation Service - handles privileged operations for Chrome/Edge updates that require elevated permissions.

elevation_service.exe is the 418th most commonly executed Windows program in EchoTrail's dataset, observed 17,274 times across enterprise environments. It typically runs from C:\Program Files (x86)\AVAST Software\Browser\Application\77.2.2152.121 and it is most often launched by services.exe.

Get this in your tools

The same record for elevation_service.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/elevation_service.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

418th
most commonly executed Windows program
17,274
observed endpoint executions

Behavior

Top Paths

  • C:\Program Files (x86)\AVAST Software\Browser\Application\77.2.2152.12111.26%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\77.0.1801.767.72%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\86.1.6937.1995.63%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\79.0.3060.803.44%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\83.1.4957.1173.18%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\80.1.3901.1632.5%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\84.1.5543.1362.21%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\80.0.3764.1501.96%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\87.0.7478.891.93%
  • C:\Program Files (x86)\AVAST Software\Browser\Application\80.0.3619.1331.92%
  • C:\Program Files\Google\Chrome\Application\153.0.8010.37

Top Hashes (SHA256)

  • bf9b44cf498787bdd77410b3418a82f519420409bad21599e1b8afde0879839f11.26%
  • fbe516fbe9ac8ad7d5a671b8f7e123a012926ebe119906cca3a68e34497dd88f7.72%
  • d7d2837ce9d06cf95b342d2b8cff88950acc39401a2e78ac20d26c3acf38d41b5.63%
  • e64135349b3010eb6027d2974779353d123973352b2301a3d9ee92a0c2ebbd1e3.45%
  • 38c9f848bca30a131600031e67da298c69e0e2d2e816b58d974c3e132ec65b0b3.18%
  • 81597e158975554b8b15aa5ea361f2e80a95751a1d43c0623ccb9c5b2f2ce0b32.5%
  • 1240ad4816c0fee5a2b042677fc535c1cf89f2a9ca93d4dcb184552e6a445add2.21%
  • 901c91dfafc67bda30a0b015511d52f2e5b425ba8e280ba1bdeb59624b824f801.96%
  • ceff3607d5845ebc6c36e74e30bbc2db54aafdd06b2b89ed562b366226e3c9a81.93%
  • 01a525727a056a61514c899e7265a991caf1274c2654d98312fe82d99cea32231.92%
  • b08051f0db485076253480e8bc97438e1831c57202eea081d7f96e936e54dc00

Process Ancestry

Top Grandparents

Top Parents

Top Children

Lab record

Installed from
winget Google.Chrome 153.0.8010.37
Publisher
Google LLC
Persistence
1 service
Network
none
Command lines
1 pattern (6 launches)
DLL loads
35 patterns (191 loads)
Registry writes
0 patterns (0 writes)
File writes
0 patterns (0 writes)
HTTP requests
0 patterns (0 requests)
TLS connections
0 patterns (0 handshakes)
Named pipes
0 patterns (0 events)
Process access
1 pattern (2 events)
Driver loads
0 patterns (0 loads)
PowerShell blocks
0 patterns (0 blocks)
Remote threads
0 patterns (0 events)
Audit events
0 patterns (0 events)

Full record on Team.

Ask Rocky about elevation_service.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for elevation_service.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.