AppVLP.exe
Summary
Microsoft App-V Application Launch Point. Launches applications within the App-V virtualization environment. Abused as a LOLBin to execute commands within the App-V virtual context, bypassing application control policies.
AppVLP.exe is the 1554th most commonly executed Windows program in EchoTrail's dataset, observed 629 times across enterprise environments. It typically runs from C:\Program Files (x86)\Microsoft Office\root\Client and it is most often launched by svchost.exe.
Behavior
Top Paths
- C:\Program Files (x86)\Microsoft Office\root\Client88.55%
- C:\Program Files\Microsoft Office\root\Client11.45%
Top Hashes (SHA256)
- 19ad5b4082528c43b42cb95c68c0b5c4e6cdddae660b7597c64b3c74f7683c0430.37%
- 09f5cc79be1cf58f9afa72d3aa23cbe3c1cfd30c5e8b113dd0e5bcb4306c11fa20.35%
- c7f54054daf2c21c7cab8c6a395cfe54e58bf4f14c3b7fac15542556cd3e35cf17.17%
- 2b4c08a45b25a4d8f0bd4c80934f69176afffa54202e33e89dfb4e54f9ff550911.61%
- 234317e8ff5cb4c2fa2808c63abbb6ce7641b935c74d50ac63355fece4f6dd756.84%
- 29706e31af945456f1f5d2d094a58a6db7044646a9445b91d3b0ed3d504b73775.25%
- 2e05f34a708296bea931634825173d3d0fe9e8ddf228eacd322ed759fd9e77873.5%
- cc8538e6a15df9ee15a62be2594e52e71d16534757b3d0a30516377875e680422.07%
- 05a2e086c96266d33ea95f19096fcacdcd436176dbc687c7e737e12314175b831.27%
- f672b551f3c18152e9f340b2ef087e0a01ea160fdbb5b61be1ef5fa1b620e47c1.11%
Process Ancestry
Top Grandparents
- userinit.exe64.65%
- svchost.exe21.21%
- services.exe14.14%
Top Parents
- svchost.exe83.33%
- explorer.exe16.67%
Top Children
- msoasb.exe48.7%
- rundll32.exe39.57%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does AppVLP.exe normally do?
Present on systems with App-V (Application Virtualization) client installed. Launches applications inside the App-V virtual environment. Part of Microsoft enterprise application deployment.
When is AppVLP.exe suspicious?
Launching cmd.exe, powershell.exe, or other LOLBins. Execution on systems not using App-V. Used to launch processes that bypass AppLocker or WDAC policies.
How do attackers abuse AppVLP.exe?
PROXY EXECUTION: appvlp.exe can launch arbitrary executables within the App-V virtual environment. Because it runs as a trusted Microsoft binary, processes launched through it may bypass AppLocker/WDAC rules. Example: "appvlp.exe powershell.exe" launches PowerShell in a context that may evade application whitelisting.
Detection guidance
HIGH-CONFIDENCE: appvlp.exe launching cmd.exe, powershell.exe, or other scripting engines. MEDIUM-CONFIDENCE: Any appvlp.exe execution on systems not using App-V. DATA SOURCES: Process creation (Sysmon 1)
False positive notes
Legitimate in App-V deployments where virtualized applications are launched through appvlp.exe.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about AppVLP.exe
Rocky answers questions about AppVLP.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.