AppVLP.exe

by Microsoft
Operating SystemLOLBinmedium risk

Summary

Microsoft App-V Application Launch Point. Launches applications within the App-V virtualization environment. Abused as a LOLBin to execute commands within the App-V virtual context, bypassing application control policies.

AppVLP.exe is the 1554th most commonly executed Windows program in EchoTrail's dataset, observed 629 times across enterprise environments. It typically runs from C:\Program Files (x86)\Microsoft Office\root\Client and it is most often launched by svchost.exe.

1554th
most commonly executed Windows program
629
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Program Files (x86)\Microsoft Office\root\Client88.55%
  • C:\Program Files\Microsoft Office\root\Client11.45%

Top Hashes (SHA256)

  • 19ad5b4082528c43b42cb95c68c0b5c4e6cdddae660b7597c64b3c74f7683c0430.37%
  • 09f5cc79be1cf58f9afa72d3aa23cbe3c1cfd30c5e8b113dd0e5bcb4306c11fa20.35%
  • c7f54054daf2c21c7cab8c6a395cfe54e58bf4f14c3b7fac15542556cd3e35cf17.17%
  • 2b4c08a45b25a4d8f0bd4c80934f69176afffa54202e33e89dfb4e54f9ff550911.61%
  • 234317e8ff5cb4c2fa2808c63abbb6ce7641b935c74d50ac63355fece4f6dd756.84%
  • 29706e31af945456f1f5d2d094a58a6db7044646a9445b91d3b0ed3d504b73775.25%
  • 2e05f34a708296bea931634825173d3d0fe9e8ddf228eacd322ed759fd9e77873.5%
  • cc8538e6a15df9ee15a62be2594e52e71d16534757b3d0a30516377875e680422.07%
  • 05a2e086c96266d33ea95f19096fcacdcd436176dbc687c7e737e12314175b831.27%
  • f672b551f3c18152e9f340b2ef087e0a01ea160fdbb5b61be1ef5fa1b620e47c1.11%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does AppVLP.exe normally do?

Present on systems with App-V (Application Virtualization) client installed. Launches applications inside the App-V virtual environment. Part of Microsoft enterprise application deployment.

When is AppVLP.exe suspicious?

Launching cmd.exe, powershell.exe, or other LOLBins. Execution on systems not using App-V. Used to launch processes that bypass AppLocker or WDAC policies.

How do attackers abuse AppVLP.exe?

PROXY EXECUTION: appvlp.exe can launch arbitrary executables within the App-V virtual environment. Because it runs as a trusted Microsoft binary, processes launched through it may bypass AppLocker/WDAC rules. Example: "appvlp.exe powershell.exe" launches PowerShell in a context that may evade application whitelisting.

Detection guidance

HIGH-CONFIDENCE: appvlp.exe launching cmd.exe, powershell.exe, or other scripting engines. MEDIUM-CONFIDENCE: Any appvlp.exe execution on systems not using App-V. DATA SOURCES: Process creation (Sysmon 1)

False positive notes

Legitimate in App-V deployments where virtualized applications are launched through appvlp.exe.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about AppVLP.exe

Rocky answers questions about AppVLP.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.