NisSrv.exe

by Microsoft
Endpoint Security

Sources: 300M+ executions observed in the wild.

Summary

Windows Defender Network Inspection Service - performs real-time network traffic inspection for known vulnerability exploits and malicious patterns.

NisSrv.exe is the 586th most commonly executed Windows program in EchoTrail's dataset, observed 8,284 times across enterprise environments. It typically runs from C:\ProgramData\... and it is most often launched by services.exe.

Get this in your tools

The same record for nissrv.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/nissrv.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

586th
most commonly executed Windows program
8,284
observed endpoint executions

Behavior

Top Paths

  • C:\ProgramData\...92.01%
  • C:\Program Files\Windows Defender7.77%
  • C:\Program Files\Microsoft Security Client0.22%

Top Hashes (SHA256)

  • 1a6c31f6cfae5564b30fee34901da377f22dde3174bb4be0ce0c678faf77d6105.57%
  • 7441b012d69115ca8084128f709ec2052c9a24e7b7f6ed54e1fa1869b44e3e034.54%
  • 2e0e9650f1be1f20d106ec38aca36b35658f161e1901e412e5ae535f72f5b5db3.68%
  • 7ccd14995f2a1f76c5d52d22560ba310eca926a3d3569e1f797e7a4289b963c73.36%
  • 5eeb0a2b903901f3d408ea8b9baeceb9ccf341cf2933084510c3f0ba5a59d18d3.23%
  • 6d7f3813f39a016301218fe0437113ceee46fecbbe044e68a6a97a70cd867f1c3.12%
  • d794aba0126c332d7391a3af6dca785d1787856198d451112a2ec91ca282ecf32.79%
  • 8ea604e9f8cd45190ce102884422513021caace211d04e8014e5f3d6884f41e92.77%
  • 82a23ab40462390469ac72c952bd40f21b3ecd254cc7ee6118049644351aa7a22.73%
  • b147e146abe9f2187f2f06798f34a312ee316d43d7cf6c0b7ea3e792e07953fe2.55%

Process Ancestry

Top Grandparents

Top Parents

Security Analysis

What does NisSrv.exe normally do?

Runs as part of Windows Defender to inspect network traffic for exploit patterns. Part of the Network Inspection System (NIS).

When is NisSrv.exe suspicious?

Not running when Defender is active. Service disabled unexpectedly.

False positive notes

Normal Windows Defender component.

Related Processes

Ask Rocky about NisSrv.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for NisSrv.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.