splunk-wmi.exe
Sources: 300M+ executions observed in the wild.
Summary
Remote Performance monitor using WMI
splunk-wmi.exe is the 3784th most commonly executed Windows program in EchoTrail's dataset, observed 42 times across enterprise environments. It typically runs from C:\Program Files\Splunk\bin and it is most often launched by splunkd.exe.
Get this in your tools
The same record for splunk-wmi.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/splunk-wmi.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
3784th
most commonly executed Windows program
42
observed endpoint executions
Behavior
Top Paths
- C:\Program Files\Splunk\bin52.38%
- C:\Program Files\SplunkUniversalForwarder\bin42.86%
- C:\Program Files\SUFwd\bin4.76%
Top Hashes (SHA256)
- 0466282f623514c375d6cf521e4c337b05a0d0c5a34c1992bed8b510a20a894d90%
- 975e07e0f0b00c9e53e19b436c4d8dfbb87775736605edf66274850df2fb572210%
Process Ancestry
Top Grandparents
- services.exe100%
Top Parents
- splunkd.exe100%
Ask Rocky about splunk-wmi.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for splunk-wmi.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.