splunk-powershell.exe
Sources: 300M+ executions observed in the wild.
Summary
Splunk PowerShell module process. Executes PowerShell-based data collection scripts for the Splunk Universal Forwarder, collecting Windows event logs, performance data, and other telemetry.
splunk-powershell.exe is the 177th most commonly executed Windows program in EchoTrail's dataset, observed 87,246 times across enterprise environments. It typically runs from C:\Program Files\Splunk\bin and it is most often launched by splunkd.exe.
Get this in your tools
The same record for splunk-powershell.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/splunk-powershell.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Program Files\Splunk\bin75.57%
- C:\Program Files\SUFwd\bin22.87%
- C:\Program Files\SplunkUniversalForwarder\bin1.56%
Top Hashes (SHA256)
- 950dff45af9486ef9a6a8926be0150c733d1ecfaa501370c9ee7495e73827dab93.62%
- f9d7ca4f228a5a7cde420f872a183be91ed60fcc25c5fb9540c36df4a92654346.38%
Process Ancestry
Top Grandparents
- services.exe100%
Top Parents
- splunkd.exe100%
Top Children
- conhost.exe100%
Security Analysis
What does splunk-powershell.exe normally do?
Part of Splunk Universal Forwarder installation. Runs PowerShell collection scripts.
When is splunk-powershell.exe suspicious?
Running from outside Splunk installation directories.
How do attackers abuse splunk-powershell.exe?
Not directly abused.
Detection guidance
No detection needed. Presence indicates Splunk forwarder deployment.
False positive notes
Normal Splunk operation.
Related Processes
Ask Rocky about splunk-powershell.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for splunk-powershell.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.