elevation_service.exe
Sources: 300M+ executions observed in the wild and observed in the EchoTrail lab on Windows 11.
Summary
Browser Elevation Service - handles privileged operations for Chrome/Edge updates that require elevated permissions.
elevation_service.exe is the 418th most commonly executed Windows program in EchoTrail's dataset, observed 17,274 times across enterprise environments. It typically runs from C:\Program Files (x86)\AVAST Software\Browser\Application\77.2.2152.121 and it is most often launched by services.exe.
Get this in your tools
The same record for elevation_service.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/elevation_service.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Program Files (x86)\AVAST Software\Browser\Application\77.2.2152.12111.26%
- C:\Program Files (x86)\AVAST Software\Browser\Application\77.0.1801.767.72%
- C:\Program Files (x86)\AVAST Software\Browser\Application\86.1.6937.1995.63%
- C:\Program Files (x86)\AVAST Software\Browser\Application\79.0.3060.803.44%
- C:\Program Files (x86)\AVAST Software\Browser\Application\83.1.4957.1173.18%
- C:\Program Files (x86)\AVAST Software\Browser\Application\80.1.3901.1632.5%
- C:\Program Files (x86)\AVAST Software\Browser\Application\84.1.5543.1362.21%
- C:\Program Files (x86)\AVAST Software\Browser\Application\80.0.3764.1501.96%
- C:\Program Files (x86)\AVAST Software\Browser\Application\87.0.7478.891.93%
- C:\Program Files (x86)\AVAST Software\Browser\Application\80.0.3619.1331.92%
- C:\Program Files\Google\Chrome\Application\153.0.8010.37
Top Hashes (SHA256)
- bf9b44cf498787bdd77410b3418a82f519420409bad21599e1b8afde0879839f11.26%
- fbe516fbe9ac8ad7d5a671b8f7e123a012926ebe119906cca3a68e34497dd88f7.72%
- d7d2837ce9d06cf95b342d2b8cff88950acc39401a2e78ac20d26c3acf38d41b5.63%
- e64135349b3010eb6027d2974779353d123973352b2301a3d9ee92a0c2ebbd1e3.45%
- 38c9f848bca30a131600031e67da298c69e0e2d2e816b58d974c3e132ec65b0b3.18%
- 81597e158975554b8b15aa5ea361f2e80a95751a1d43c0623ccb9c5b2f2ce0b32.5%
- 1240ad4816c0fee5a2b042677fc535c1cf89f2a9ca93d4dcb184552e6a445add2.21%
- 901c91dfafc67bda30a0b015511d52f2e5b425ba8e280ba1bdeb59624b824f801.96%
- ceff3607d5845ebc6c36e74e30bbc2db54aafdd06b2b89ed562b366226e3c9a81.93%
- 01a525727a056a61514c899e7265a991caf1274c2654d98312fe82d99cea32231.92%
- b08051f0db485076253480e8bc97438e1831c57202eea081d7f96e936e54dc00
Process Ancestry
Top Grandparents
- wininit.exe100%
Top Parents
- services.exe100%
Top Children
- setup.exe97.13%
Lab record
- Installed from
- winget Google.Chrome 153.0.8010.37
- Publisher
- Google LLC
- Persistence
- 1 service
- Network
- none
- Command lines
- 1 pattern (6 launches)
- DLL loads
- 35 patterns (191 loads)
- Registry writes
- 0 patterns (0 writes)
- File writes
- 0 patterns (0 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 0 patterns (0 handshakes)
- Named pipes
- 0 patterns (0 events)
- Process access
- 1 pattern (2 events)
- Driver loads
- 0 patterns (0 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 0 patterns (0 events)
Full record on Team.
Ask Rocky about elevation_service.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for elevation_service.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.