mmc.exe

by Microsoft
System Utilitymedium risk

Sources: 300M+ executions observed in the wild.

Summary

Microsoft Management Console - hosts administrative snap-ins for Windows management (Event Viewer, Disk Management, Group Policy Editor, etc.).

mmc.exe is the 717th most commonly executed Windows program in EchoTrail's dataset, observed 4,953 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by explorer.exe.

Get this in your tools

The same record for mmc.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/mmc.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

717th
most commonly executed Windows program
4,953
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System3299.45%
  • C:\Windows\SysWOW640.55%

Top Hashes (SHA256)

  • de2dbc557fec030b9150902d2e2525374fc7063f469516e41d561321afce089b26.18%
  • 0cd33cc6d292d52b8c6e530158185502e47ecef0c47d92ac7a097ef1bbced0bc8.81%
  • e021d4b2f12d2836c279aeee9fe59cea300730519afa57f450ba7095b45a653f8.6%
  • 683c0cb518b3fe31cffa7fcf79f5efc18d355c6d52734757758ed26ae59500377.4%
  • 97faabad1d93225121e347462133bb768f3ad7d4b27ac8c232594cc205ca8d3b7.4%
  • 03048f7a610ee24ca36007019c6d5d200a9e94172d7f7a46cf71d7e792163e8d4.39%
  • b0ad764277fb78de24e0ef08e439a8e5690b11d91b8f772034d94315bf7b7e453.11%
  • a82964cea41cfc27d745612e251494c70fef429becd4b83fe97e01741341658d3.01%
  • 5dc0efc7cf971f9da9bd183f4bc5707176f7f829133b3ef90ffbb603516af9212.96%
  • a08ec9d2f811726bdcd71f7c5b40cdb543d092c11811a45180e569fe3f62124d2.61%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does mmc.exe normally do?

Loads .msc snap-in files for system administration. Common snap-ins: eventvwr.msc, diskmgmt.msc, gpedit.msc, services.msc.

When is mmc.exe suspicious?

Loading snap-ins from unusual paths. Loading non-standard .msc files. Running on workstations without admin tooling expected.

How do attackers abuse mmc.exe?

Attackers can craft malicious .msc files that execute arbitrary commands when opened in MMC. MMC can also be used to load COM objects for code execution. The GrimResource technique uses crafted .msc files for initial access.

Detection guidance

Monitor for mmc.exe loading .msc files from temp directories or user-writable paths. Alert on mmc.exe spawning unexpected child processes.

False positive notes

System administrators routinely use MMC snap-ins. RSAT tools rely heavily on MMC.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about mmc.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for mmc.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.