mountvol.exe

by Microsoft
System Utility

Sources: 300M+ executions observed in the wild.

Summary

Volume Mount Point manager. Creates, lists, or removes volume mount points. Can expose hidden volumes or access volumes without drive letters assigned.

mountvol.exe is the 1572nd most commonly executed Windows program in EchoTrail's dataset, observed 613 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by Snagit32.exe.

Get this in your tools

The same record for mountvol.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/mountvol.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

1572nd
most commonly executed Windows program
613
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System3288.25%
  • C:\Windows\SysWOW6411.75%

Top Hashes (SHA256)

  • caf29650446db3842e1c1e8e5e1bafadaf90fc82c5c37b9e2c75a089b747613148.11%
  • 7db6a524b2070a9bcb96062323f2f4424fbcf406e479f237cb96ede03e42307938.1%
  • 1031661048c6ef1cd70b29470d9b012c6f18c6e2d81bc7e8862f6c2223c0e0bb4.6%
  • c10d0b4ced9c19e4c6a73be211db4bc0ee9aff33b72aa2c90f38d1ebd9b197093.12%
  • 1f649f2b822a87b6c54524e20975946df0f8081ca1325cf781a9e50c66801f6b2.63%
  • 83a39941991e31834991558b4a6f4b482ad806c4707406dfbf5ef274f8cc6d991.81%
  • f247be88f22b07a36f4b71707ed7a96bd989bad37a7500da03b81709749ded7e1.31%
  • 4ebeffcf6a8be337857f48b8b6cc6a96483889cee98857c475f138e59b1dd9ca0.33%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does mountvol.exe normally do?

Runs from C:\Windows\System32. Used during disk management to create mount points for volumes without drive letters. Admin-only operation.

When is mountvol.exe suspicious?

Mounting hidden or recovery partitions. Execution by non-admin users. Used in combination with data collection tools.

How do attackers abuse mountvol.exe?

DIRECT VOLUME ACCESS: mountvol can expose volumes that don't have drive letters, including recovery partitions or hidden volumes that may contain sensitive data or backup credentials.

Detection guidance

LOW-PRIORITY: Monitor for unusual mount point creation. DATA SOURCES: Process creation (Sysmon 1)

False positive notes

Disk management operations, storage configuration, and backup tools legitimately use mountvol.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about mountvol.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for mountvol.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.