sethc.exe
Sources: 300M+ executions observed in the wild.
Summary
Windows Sticky Keys accessibility feature - triggered by pressing Shift 5 times. Runs before user logon, making it a classic backdoor target.
sethc.exe is the 764th most commonly executed Windows program in EchoTrail's dataset, observed 4,304 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by AtBroker.exe.
Get this in your tools
The same record for sethc.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/sethc.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 657772f455381f04832951c0dbfeffe98ac0d680f1578580212ce8772d27d1b241.1%
- d94449fb04faf4c6200d00962de1a93ee85ee76544bee786d631c13a641d02b717.85%
- b43e2b2ee125966e831c21eccb5622060749d73832361bd92dd3db22225f7cbd9.54%
- e0bf9845f79c1b4fa09e334f460b6ef70f418eb46cd61b696dec772c6ff3839d8.14%
- 52a9e16b777d1ffbba54a686f9d77ae0aa622ec2fd7a501cea398b7a53e647937.01%
- 2dfcaa75bfb6efbd24a0862c80f90798be480f656a434c5ace7eeb618835c78a4.13%
- aea110ee0865635ee764b1b40409db3a3165e57efff4caf942bcd8982f3063c52.95%
- 615b2f2d7e3fce340839a9b54bdc3445eb2333d0fafee477d6113379e90935b82.11%
- f7056041988a7ca29ff6c341a1f9efe94c90c2cf47e9078acab3b97f1f18e1232.02%
- 746d48a2fc0198e20c6abcb301ed5c0ffebde33d0c0c890044ec98c9ee5e21ec1.99%
Process Ancestry
Top Grandparents
- winlogon.exe87.19%
- smss.exe12.75%
- svchost.exe0.06%
Top Parents
- AtBroker.exe85.15%
- winlogon.exe14.36%
- utilman.exe0.35%
Top Children
Security Analysis
What does sethc.exe normally do?
Runs when a user presses Shift 5 times to enable Sticky Keys accessibility feature. Executes at the logon screen with SYSTEM privileges.
When is sethc.exe suspicious?
sethc.exe replaced with another binary (cmd.exe). sethc.exe spawning command shells. File hash mismatch from known-good baseline.
How do attackers abuse sethc.exe?
Classic backdoor technique: replace sethc.exe with cmd.exe to get a SYSTEM-level command prompt at the logon screen by pressing Shift 5 times. Provides pre-authentication access to compromised systems, especially via RDP.
Detection guidance
Monitor sethc.exe file integrity (hash comparison). Alert on sethc.exe spawning child processes (especially cmd.exe). Detect file replacement via Sysmon File Create events targeting sethc.exe.
False positive notes
Legitimate Sticky Keys activation by users with accessibility needs. Should not spawn child processes.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about sethc.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for sethc.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.