mountvol.exe
Sources: 300M+ executions observed in the wild.
Summary
Volume Mount Point manager. Creates, lists, or removes volume mount points. Can expose hidden volumes or access volumes without drive letters assigned.
mountvol.exe is the 1572nd most commonly executed Windows program in EchoTrail's dataset, observed 613 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by Snagit32.exe.
Get this in your tools
The same record for mountvol.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/mountvol.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\System3288.25%
- C:\Windows\SysWOW6411.75%
Top Hashes (SHA256)
- caf29650446db3842e1c1e8e5e1bafadaf90fc82c5c37b9e2c75a089b747613148.11%
- 7db6a524b2070a9bcb96062323f2f4424fbcf406e479f237cb96ede03e42307938.1%
- 1031661048c6ef1cd70b29470d9b012c6f18c6e2d81bc7e8862f6c2223c0e0bb4.6%
- c10d0b4ced9c19e4c6a73be211db4bc0ee9aff33b72aa2c90f38d1ebd9b197093.12%
- 1f649f2b822a87b6c54524e20975946df0f8081ca1325cf781a9e50c66801f6b2.63%
- 83a39941991e31834991558b4a6f4b482ad806c4707406dfbf5ef274f8cc6d991.81%
- f247be88f22b07a36f4b71707ed7a96bd989bad37a7500da03b81709749ded7e1.31%
- 4ebeffcf6a8be337857f48b8b6cc6a96483889cee98857c475f138e59b1dd9ca0.33%
Process Ancestry
Top Grandparents
Top Parents
- Snagit32.exe46%
- SnagitEditor.exe42.09%
- cmd.exe8.81%
Top Children
- conhost.exe100%
Security Analysis
What does mountvol.exe normally do?
Runs from C:\Windows\System32. Used during disk management to create mount points for volumes without drive letters. Admin-only operation.
When is mountvol.exe suspicious?
Mounting hidden or recovery partitions. Execution by non-admin users. Used in combination with data collection tools.
How do attackers abuse mountvol.exe?
DIRECT VOLUME ACCESS: mountvol can expose volumes that don't have drive letters, including recovery partitions or hidden volumes that may contain sensitive data or backup credentials.
Detection guidance
LOW-PRIORITY: Monitor for unusual mount point creation. DATA SOURCES: Process creation (Sysmon 1)
False positive notes
Disk management operations, storage configuration, and backup tools legitimately use mountvol.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about mountvol.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for mountvol.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.