msdtc.exe
Sources: 300M+ executions observed in the wild.
Summary
Microsoft Distributed Transaction Coordinator - coordinates transactions spanning multiple resource managers (databases, message queues) across networked systems.
msdtc.exe is the 1026th most commonly executed Windows program in EchoTrail's dataset, observed 1,917 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.
Get this in your tools
The same record for msdtc.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/msdtc.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 8a335c28fe1ef96dd71485877f2e86155d24b5614ace05468f4b07e2acd5633119.09%
- 72db45ca11fe635df9f8273c38cbefb8df5362ada0cbf6d2b1e570365dc700c016.13%
- ee84158da9a863daa633092f691761952de7888af01fd8020761cfd232e3bc8811.45%
- 8ddc6d67a14b549946d103f2a5e7b1eb23c68bb6e7b8ecbc192365c7323ec4588.44%
- 73c0829f641f62cbfc0523ed54d94121e3a694eccf148dbf4a5743631badb7147.37%
- edfe71025c352d0dabec7b9506c5945bb0ec11f8db540db8cb1116c2ea1648a87.1%
- 2fbbec4cacb5161f68d7c2935852a5888945ca0f107cf8a1c01f4528ce407de36.45%
- 1eab4b9691e9efa1da02bdcb84035f65eda4b525e5aee925a6e1e4107f8e4f315.59%
- 30b22ca09018d865a09efce286150072ebba5ad52b587e50404101d8db090c1e4.57%
- 4cafce804d9135be9cbf80307d570f24e4a102890dab504e3deff3b335c9b80e4.41%
Process Ancestry
Top Grandparents
- wininit.exe99.81%
Top Parents
- services.exe93.96%
- cmd.exe0.05%
Security Analysis
What does msdtc.exe normally do?
Runs as a service on systems using distributed transactions (SQL Server, COM+, BizTalk). Coordinates two-phase commit across multiple databases.
When is msdtc.exe suspicious?
DLL loading from non-standard paths. Running on systems that do not use distributed transactions. Spawning unexpected child processes.
How do attackers abuse msdtc.exe?
MSDTC loads DLLs from a configurable path and has been used for DLL side-loading attacks. Attackers can place malicious DLLs in the MSDTC working directory for persistence and execution as SYSTEM.
Detection guidance
Monitor DLLs loaded by msdtc.exe. Alert on non-standard DLL paths. Detect modifications to the MSDTC service configuration.
False positive notes
Normal on SQL Server and application servers using distributed transactions.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about msdtc.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for msdtc.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.