quser.exe

by Microsoft
Operating Systemmedium risk

Sources: 300M+ executions observed in the wild.

Summary

Query User (quser.exe) displays information about user sessions on a Remote Desktop Session Host server or local machine. It shows logged-on users, session names, session IDs, session state, idle time, and logon time.

quser.exe is the 14th most commonly executed Windows program in EchoTrail's dataset, observed 4,948,346 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by LTSVC.exe.

Get this in your tools

The same record for quser.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/quser.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

14th
most commonly executed Windows program
4,948,346
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 50557fd5ad11afb07926d1fc5e84de247183a0ebc184f5d02b142db126d90fb875.62%
  • 67d4ff2489b1c4e78928ca9ac9c1a79782a30bb976dc1ae49ac667cd5ac344a89.82%
  • 766c791edfa6eeeba0f99d6481bfe23bf59e6acb81a930b71f3aa33efbafe5449.69%
  • 84f53f3f001d06a6e74e185be9d6f943db4344e47f8a4ef8702c35aeb8703fa03.69%
  • 69d5fcc7ad1f3ec8f8bae99d61672ff9cc46e3819a77981660ee50c56e526eaf0.75%
  • d93f1b0a06fe6426871fd0b07f80512e984fedd5c9a1397c39509a94ffa4a57e0.32%
  • 1e6e72caa1950857a7771d3aa6131264214d12cdb1587c0a89d2f6d010db251e0.11%
  • 363d202d3c269dee639dc437b5d190b4ff8ecbb3807b70dfdfe08d7355976fa3<0.01%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does quser.exe normally do?

Located in C:\Windows\System32. In this dataset, almost exclusively launched by LTSVC.exe (LabTech/ConnectWise management agent) for session monitoring. Also occasionally launched by query.exe or cmd.exe. Spawns conhost.exe.

When is quser.exe suspicious?

When used as part of a manual discovery sequence alongside whoami, net user, net group, qwinsta — indicates user enumeration. Spawned by unusual parents (wmiprvse.exe, w3wp.exe) suggesting remote execution. Not typically suspicious in isolation due to its heavy use by management agents.

How do attackers abuse quser.exe?

User discovery: attackers use quser to identify logged-on users and active sessions, particularly on RDP servers. Helps identify target accounts for credential theft or session hijacking. Part of common discovery scripts during post-exploitation.

Detection guidance

Do not alert on quser.exe alone — management agents make this too noisy. Medium-confidence: quser as part of a reconnaissance sequence with other user/session discovery commands from the same parent process. Correlate with parent process to distinguish agent automation from interactive attacker activity.

False positive notes

LabTech/ConnectWise (LTSVC.exe) accounts for the vast majority of quser executions in this dataset. Many RMM tools monitor user sessions via quser. System administrators routinely use quser on RDP servers.

MITRE ATT&CK techniques

Related Processes

cmd.exequery.exeqwinsta.exe

Ask Rocky about quser.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for quser.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.