pdq migrate.exe
by PDQ.com Corporation
Sources: observed in the EchoTrail lab on Windows 11.
Summary
PDQ Migrate (PDQ Migrate, PDQ Migrate)
pdq migrate.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-29 installed from zip_url package https://services.pdq.com/download/pdq-migrate/pdq-migrate-latest.zip.
Get this in your tools
The same record for pdq migrate.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/pdq%20migrate.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
n/a
most commonly executed Windows program
n/a
observed endpoint executions
Behavior
Top Paths
- C:\lab\in
Top Hashes (SHA256)
- 7b060e88d4380b19f9e09581ab047c6e4d5f0fa3fe25881d88c0097c66d93a31
Process Ancestry
Top Grandparents
Top Parents
Lab record
- Installed from
- zip_url https://services.pdq.com/download/pdq-migrate/pdq-migrate-latest.zip
- Publisher
- PDQ.com Corporation
- Persistence
- none
- Network
- 3 destinations
- Command lines
- 1 pattern (1 launch)
- DLL loads
- 73 patterns (76 loads)
- Registry writes
- 13 patterns (44 writes)
- File writes
- 123 patterns (135 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 3 patterns (3 handshakes)
- Named pipes
- 1 pattern (1 event)
- Process access
- 0 patterns (0 events)
- Driver loads
- 0 patterns (0 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 0 patterns (0 events)
Full record on Team.
Ask Rocky about pdq migrate.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for pdq migrate.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.