fsutil.exe
Sources: 300M+ executions observed in the wild.
Summary
Windows File System Utility - performs advanced file system operations including quota management, reparse points, USN journal queries, and sparse file management.
fsutil.exe is the 963rd most commonly executed Windows program in EchoTrail's dataset, observed 2,329 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by SRFeature.exe.
Get this in your tools
The same record for fsutil.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/fsutil.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\SysWOW6495.88%
- C:\Windows\System324.12%
Top Hashes (SHA256)
- 663176115ad56014efc43b792aead9658c3d1045cc64fe794c3ef9d4105a8f3a90.57%
- 3b13a67dd25962bb50ab60aca722b0aec4810c9c23f2f8d6e3648ad6d694b1942.78%
- c302730b6088c6e28d1d9692d4d7d512c622979e58a1f6ccec396ac1231f3de21.65%
- e9d78e39bfd9395798cc85c583ad15b0b107e17f81f3ec24b5f1bbf4ace92e141.48%
- d911c86f32f1b14f9371a0a87b57d78a97b2a9971fd15fcf562957cdc5f81d640.91%
- ec750391d52bba76bb5bbb2ff6fd53eef03b043bc48da72bac0b9c07cd0241be0.65%
- 1a988d562a72325c0e97e4be05fb311e052e12a095387754fed02b446b032a1a0.39%
- 7e791acbaa84d2d9e73c0c9dbf5e225e9b69b25d5b9af598f7802cd56f4ab01b0.39%
- 3fed60dcbc09f02746ca8789dc02748276c182901b2342c1169b6e99a55f79390.35%
- ac33f16c91283124276c3f14c9570086388999311749503af4ac55d85a15dc300.13%
Process Ancestry
Top Grandparents
- cmd.exe41.46%
- devenv.exe20.73%
- services.exe10.98%
- SRManager.exe7.32%
- explorer.exe6.1%
- vs_installer.exe6.1%
- msiexec.exe2.44%
- Unity Hub.exe2.44%
Top Parents
- SRFeature.exe85.46%
- cmd.exe3.86%
- python.exe0.34%
- SRManager.exe0.04%
Top Children
- conhost.exe100%
Security Analysis
What does fsutil.exe normally do?
Used by administrators for file system troubleshooting, quota management, and USN journal operations.
When is fsutil.exe suspicious?
Querying USN journal (file access forensics evasion). Creating very large sparse files (disk fill attacks). Querying volume information for recon. Deleting USN journal to cover tracks.
How do attackers abuse fsutil.exe?
Attackers use "fsutil usn deletejournal" to clear the USN change journal, destroying forensic evidence of file system changes. "fsutil volume diskfree" is used for system reconnaissance.
Detection guidance
Alert on USN journal deletion. Monitor for fsutil usn and fsutil volume commands. These are unusual on workstations.
False positive notes
Storage administrators and backup tools may use fsutil for quota and volume management.
Related Processes
Ask Rocky about fsutil.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for fsutil.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.