ARP.EXE

by Microsoft
System Utilitymedium risk

Summary

Windows ARP utility - displays and modifies the Address Resolution Protocol (ARP) cache, mapping IP addresses to MAC addresses.

ARP.EXE is the 795th most commonly executed Windows program in EchoTrail's dataset, observed 4,021 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by Lenovo.Modern.ImController.PluginHost.CompanionApp.exe.

795th
most commonly executed Windows program
4,021
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\SysWOW6497.07%
  • C:\Windows\System322.93%

Top Hashes (SHA256)

  • 6f928475e24f329dfd465d7b2411573b9824c317c704708e077f4732e58d015343.33%
  • cebbca243dc97da5d37620298d675341663080d7428198310805fb19eb35a41a42.81%
  • 700a0ca0ba2efedda6536ddf7905e658890e76b327942a4d8a6afa31a23450b210.2%
  • 60f270a0e99e75851ebe6eed6df8f7d50fcf07bd34445b5518b48ad8f230af450.87%
  • 7b79171410482f410b7572c58edb7fd39326f7150c7c6882249b1cf9d7c970f00.77%
  • d9b84f11fdea5a621edf3ccbb6363285c9421438f35641d306d4cd841aabd65d0.62%
  • ec54b37cdb3567f3a81384fc6abf9220ada8b2df6c087ade8c7e075687b09fa90.62%
  • 5c95e274daa0ffc07cc1f9c9669778f8c4c8eff8497be0a8a4a0591b512639ae0.35%
  • cca1f962f9435330c556f07a1745d743ad7acad7561c4c79420b0bf16c8e1d0a0.15%
  • 95446d661b61c83fc3cc8952e1a5448e662d0695aaf7787db5ec0038dd3973c20.07%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does ARP.EXE normally do?

Used by network administrators to view and manage ARP cache entries for troubleshooting.

When is ARP.EXE suspicious?

Execution by non-admin users. Running as part of a script that also calls ipconfig, netstat, net, etc. (enumeration chain). Adding static ARP entries.

How do attackers abuse ARP.EXE?

Used for network reconnaissance to discover active hosts on the local subnet. Part of common post-exploitation enumeration scripts. "arp -a" reveals all known hosts on the network segment.

Detection guidance

Monitor for arp.exe as part of enumeration chains (arp + ipconfig + netstat + net in sequence). Single invocations are usually benign; patterned execution is suspicious.

False positive notes

Network troubleshooting by IT staff. Network monitoring scripts may periodically query ARP tables.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about ARP.EXE

Rocky answers questions about ARP.EXE grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.