ARP.EXE
Summary
Windows ARP utility - displays and modifies the Address Resolution Protocol (ARP) cache, mapping IP addresses to MAC addresses.
ARP.EXE is the 795th most commonly executed Windows program in EchoTrail's dataset, observed 4,021 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by Lenovo.Modern.ImController.PluginHost.CompanionApp.exe.
Behavior
Top Paths
- C:\Windows\SysWOW6497.07%
- C:\Windows\System322.93%
Top Hashes (SHA256)
- 6f928475e24f329dfd465d7b2411573b9824c317c704708e077f4732e58d015343.33%
- cebbca243dc97da5d37620298d675341663080d7428198310805fb19eb35a41a42.81%
- 700a0ca0ba2efedda6536ddf7905e658890e76b327942a4d8a6afa31a23450b210.2%
- 60f270a0e99e75851ebe6eed6df8f7d50fcf07bd34445b5518b48ad8f230af450.87%
- 7b79171410482f410b7572c58edb7fd39326f7150c7c6882249b1cf9d7c970f00.77%
- d9b84f11fdea5a621edf3ccbb6363285c9421438f35641d306d4cd841aabd65d0.62%
- ec54b37cdb3567f3a81384fc6abf9220ada8b2df6c087ade8c7e075687b09fa90.62%
- 5c95e274daa0ffc07cc1f9c9669778f8c4c8eff8497be0a8a4a0591b512639ae0.35%
- cca1f962f9435330c556f07a1745d743ad7acad7561c4c79420b0bf16c8e1d0a0.15%
- 95446d661b61c83fc3cc8952e1a5448e662d0695aaf7787db5ec0038dd3973c20.07%
Process Ancestry
Top Grandparents
- explorer.exe18.18%
- WmiPrvSE.exe1.44%
- userinit.exe0.24%
Top Parents
- cmd.exe3.66%
- explorer.exe0.02%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does ARP.EXE normally do?
Used by network administrators to view and manage ARP cache entries for troubleshooting.
When is ARP.EXE suspicious?
Execution by non-admin users. Running as part of a script that also calls ipconfig, netstat, net, etc. (enumeration chain). Adding static ARP entries.
How do attackers abuse ARP.EXE?
Used for network reconnaissance to discover active hosts on the local subnet. Part of common post-exploitation enumeration scripts. "arp -a" reveals all known hosts on the network segment.
Detection guidance
Monitor for arp.exe as part of enumeration chains (arp + ipconfig + netstat + net in sequence). Single invocations are usually benign; patterned execution is suspicious.
False positive notes
Network troubleshooting by IT staff. Network monitoring scripts may periodically query ARP tables.
Related Processes
Ask Rocky about ARP.EXE
Rocky answers questions about ARP.EXE grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.