pscp.exe
by Simon Tatham
Sources: observed in the EchoTrail lab on Windows 11.
Summary
Command-line SCP/SFTP client (PuTTY suite, Simon Tatham)
pscp.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-10 installed from winget package PuTTY.PuTTY.
Get this in your tools
The same record for pscp.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/pscp.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
3246th
most commonly executed Windows program
n/a
observed endpoint executions
Behavior
Top Paths
- C:\Program Files\PuTTY63.01%
- C:\...36.99%
Top Hashes (SHA256)
- 9ffc7e4333d3be11b244d5f83b02ebcd194a671539f7faf1b5597d9209cc25c375.34%
- 1d673f12ddf0e6cc1545a79471fd5dd56bf0ff9ccff49ff91b41b4085b72766524.66%
- d7534e6ad0228877abbedeb221345845f3237898e07273d8a186241744895eb6
Process Ancestry
Top Grandparents
- explorer.exe98.63%
- userinit.exe1.37%
Top Parents
- cmd.exe98.63%
- explorer.exe1.37%
Top Children
- conhost.exe100%
Lab record
- Installed from
- winget PuTTY.PuTTY 0.84.0.0
- Publisher
- Simon Tatham
- Persistence
- none
- Network
- none
- Command lines
- 1 pattern (1 launch)
- DLL loads
- 18 patterns (18 loads)
- Registry writes
- 2 patterns (2 writes)
- File writes
- 0 patterns (0 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 0 patterns (0 handshakes)
- Named pipes
- 0 patterns (0 events)
- Process access
- 0 patterns (0 events)
- Driver loads
- 0 patterns (0 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 0 patterns (0 events)
Full record on Team.
Ask Rocky about pscp.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for pscp.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.