where.exe

by Microsoft
System Utility

Sources: 300M+ executions observed in the wild.

Summary

Windows file search utility. Locates files matching a pattern in the PATH or specified directories. Used in discovery to find installed tools and executables.

where.exe is the 1441st most commonly executed Windows program in EchoTrail's dataset, observed 805 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by w3wp.exe.

Get this in your tools

The same record for where.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/where.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

1441st
most commonly executed Windows program
805
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • fd9d35cae2120c38cb96d38f040737ca80e41f1fc59b1b02324efb7e091aa25591.88%
  • 4dc3fa01ba87e9204ad65668a9c92f98353a0ba370bc59f61d3eafe8c754e2486.62%
  • ade557dd65848c5cf6565913cf6e01cf5c9a8033f0d784c4d6932394958d743e0.88%
  • 0da0911372136e3a1e78a4e118f51c7b82a6e1e71580d44daa4c529d4ecd65d80.25%
  • 24db660179dfb2f36705923cf64218a8cb4f1133e63148295d5bf2219672a79e0.25%
  • f949863f5e351eeb5054f04f181fe582e98cb322100956ed938538523258440c0.12%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does where.exe normally do?

Runs from C:\Windows\System32. Used by administrators and scripts to find executables in the PATH. Common in build scripts and development workflows.

When is where.exe suspicious?

Searching for security tools (where python, where nmap, where mimikatz). Part of automated enumeration scripts. Searching for credentials or sensitive file types.

How do attackers abuse where.exe?

DISCOVERY: Used to locate installed tools that could be leveraged for further attack (python, curl, ssh, etc.) or to find specific file types. Low-risk individually but part of enumeration tradecraft.

Detection guidance

LOW-PRIORITY: Monitor as part of broader enumeration patterns rather than individually. DATA SOURCES: Process creation (Sysmon 1)

False positive notes

Extremely common in normal operations. Developers, scripts, and build tools use where.exe routinely.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about where.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for where.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.