esentutl.exe

by Microsoft
System UtilityLOLBinhigh risk

Sources: 300M+ executions observed in the wild.

Summary

Extensible Storage Engine (ESE/JET) utility - manages ESE databases used by Active Directory, Exchange, and Windows components. Can copy locked database files.

esentutl.exe is the 758th most commonly executed Windows program in EchoTrail's dataset, observed 4,378 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by AXIOMProcess.exe.

Get this in your tools

The same record for esentutl.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/esentutl.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

758th
most commonly executed Windows program
4,378
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 753feb8e2bc07b6ed0e3ba836a33ec3c6f097a237fb9d48c23938892c8a16f4a63.03%
  • 8a0bf768502c8006ceac62e3f1564e6893595170a4601e89b0f67c574ec98c4129.6%
  • a3ee005c46f1dea44f2affd99c3bd1545b7d5448cb54cf774841cf93da5a72087.37%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does esentutl.exe normally do?

Used for ESE database maintenance (defragmentation, repair, integrity checks). Legitimately used by Exchange administrators and AD maintenance tasks.

When is esentutl.exe suspicious?

Copying ntds.dit or SAM/SYSTEM registry hives. Operating on browser credential databases. Running on workstations (typically a server admin tool).

How do attackers abuse esentutl.exe?

Attackers use "esentutl.exe /y /vss ntds.dit" to copy the locked Active Directory database for offline credential extraction. Can also copy locked browser credential databases and other ESE-format files. The /y flag copies files using raw I/O, bypassing locks.

Detection guidance

Alert on esentutl.exe accessing ntds.dit, SAM, SYSTEM, or SECURITY files. Monitor for /y flag usage on sensitive database paths. Any use on workstations should be investigated.

False positive notes

Exchange and AD administrators use esentutl for database maintenance. Check whether the user has legitimate admin responsibilities.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about esentutl.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for esentutl.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.