fsutil.exe

by Microsoft
System Utilitymedium risk

Sources: 300M+ executions observed in the wild.

Summary

Windows File System Utility - performs advanced file system operations including quota management, reparse points, USN journal queries, and sparse file management.

fsutil.exe is the 963rd most commonly executed Windows program in EchoTrail's dataset, observed 2,329 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by SRFeature.exe.

Get this in your tools

The same record for fsutil.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/fsutil.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

963rd
most commonly executed Windows program
2,329
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\SysWOW6495.88%
  • C:\Windows\System324.12%

Top Hashes (SHA256)

  • 663176115ad56014efc43b792aead9658c3d1045cc64fe794c3ef9d4105a8f3a90.57%
  • 3b13a67dd25962bb50ab60aca722b0aec4810c9c23f2f8d6e3648ad6d694b1942.78%
  • c302730b6088c6e28d1d9692d4d7d512c622979e58a1f6ccec396ac1231f3de21.65%
  • e9d78e39bfd9395798cc85c583ad15b0b107e17f81f3ec24b5f1bbf4ace92e141.48%
  • d911c86f32f1b14f9371a0a87b57d78a97b2a9971fd15fcf562957cdc5f81d640.91%
  • ec750391d52bba76bb5bbb2ff6fd53eef03b043bc48da72bac0b9c07cd0241be0.65%
  • 1a988d562a72325c0e97e4be05fb311e052e12a095387754fed02b446b032a1a0.39%
  • 7e791acbaa84d2d9e73c0c9dbf5e225e9b69b25d5b9af598f7802cd56f4ab01b0.39%
  • 3fed60dcbc09f02746ca8789dc02748276c182901b2342c1169b6e99a55f79390.35%
  • ac33f16c91283124276c3f14c9570086388999311749503af4ac55d85a15dc300.13%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does fsutil.exe normally do?

Used by administrators for file system troubleshooting, quota management, and USN journal operations.

When is fsutil.exe suspicious?

Querying USN journal (file access forensics evasion). Creating very large sparse files (disk fill attacks). Querying volume information for recon. Deleting USN journal to cover tracks.

How do attackers abuse fsutil.exe?

Attackers use "fsutil usn deletejournal" to clear the USN change journal, destroying forensic evidence of file system changes. "fsutil volume diskfree" is used for system reconnaissance.

Detection guidance

Alert on USN journal deletion. Monitor for fsutil usn and fsutil volume commands. These are unusual on workstations.

False positive notes

Storage administrators and backup tools may use fsutil for quota and volume management.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about fsutil.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for fsutil.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.