adb.exe
Summary
Android Debug Bridge. Command-line tool for communicating with Android devices for development and debugging.
adb.exe is the 115th most commonly executed Windows program in EchoTrail's dataset, observed 188,393 times across enterprise environments. It typically runs from C:\Program Files\Magnet Forensics\Magnet AXIOM\AXIOM Process\ADB\adb7 and it is most often launched by AXIOMProcess.exe.
Behavior
Top Paths
- C:\Program Files\Magnet Forensics\Magnet AXIOM\AXIOM Process\ADB\adb792.96%
- C:\Program Files\Genymobile\Genymotion\tools4.29%
- C:\Program Files (x86)\Magnet Acquire\ADB\adb72.52%
- C:\Program Files (x86)\WugFresh Development\Nexus Root Toolkit\data0.16%
- C:\Users\...0.04%
- C:\Program Files (x86)\EaseUS\Todo Backup\bin0.02%
- C:\Program Files (x86)\FonePaw\FonePaw DoTrans\adb<0.01%
- C:\Program Files (x86)\Android\android-sdk\platform-tools<0.01%
- C:\Program Files\Microvirt\MEmu<0.01%
- C:\Program Files (x86)\Magnet Acquire\ADB<0.01%
Top Hashes (SHA256)
- 28c7f9efc61632cb8437fe58de2ec8f615f8e0bba17819f05651903c0f68e9af90.9%
- bbe9ae11b27bfecd4f5f0b981cddf235e5e703572e367a931b94ecbf6cfe17aa5.28%
- b40abda76f72462483a95321caf431b752b7988de0f92bcb0ba27bf6e3b86bfc3.53%
- 46663d96f3d26040a4928a521d75d6669c9ee1ed315a32681b7a6399995da6030.19%
- a3887975396c74b6d4bdb49d2030881165e09b4ed89b0c7bbaf4b821d44d46430.05%
- 1bff6a77f984abaef62e43aef721cb5bb54a1ff08c5946eb2d6530c8df0b40430.03%
- 71489c655f1a33cd463c652798caa85725780cb8c1f93d05f13fe29de31ab1e30.01%
- 348179b6593cf255bed4f79df4f298a8d449230f596ae033e29f5d28647803b70.01%
- 259f7767bd3d218af14d82b9876276df395870b47c8548c717c6afee068a5a0c<0.01%
- c30394cfaa86ed8914e8becae2ee94bdd476d6aee6b840ed08eed379bc66f6b9<0.01%
Process Ancestry
Top Grandparents
- explorer.exe63.23%
- AXIOMProcess.exe17.15%
- wyupdate.exe0.29%
- services.exe0.09%
- cmd.exe0.04%
- unins000.exe<0.01%
Top Parents
- AXIOMProcess.exe73.23%
- adb.exe20.39%
- cmd.exe0.19%
- agent.exe0.02%
- devenv.exe<0.01%
Top Children
- conhost.exe79.57%
- adb.exe20.43%
- WerFault.exe<0.01%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does adb.exe normally do?
Part of Google (Android SDK) software.
When is adb.exe suspicious?
Running from unexpected paths.
How do attackers abuse adb.exe?
Not commonly abused.
Detection guidance
No specific detection needed.
False positive notes
Normal operation.
Ask Rocky about adb.exe
Rocky answers questions about adb.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.