Dism.exe
Summary
Deployment Image Servicing and Management - manages Windows images, features, packages, and drivers. Can enable/disable Windows features and service offline images.
Dism.exe is the 797th most commonly executed Windows program in EchoTrail's dataset, observed 3,994 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by cmd.exe.
Behavior
Top Paths
- C:\Windows\System3299.75%
- C:\Windows\SysWOW640.15%
- C:\Program Files (x86)\Windows Kits\Assessment and Deployment Kit\Deployment Tools\amd64\DISM0.1%
Top Hashes (SHA256)
- 1687c9fffd9a9db09bd43ad192baedaa43b95d1c0a6a9f3d37bf4c0565fa26c622.75%
- 2fbff06b431e9b0144bfc689e94257b77f9a8f91f03af4851bd100278415a66719.05%
- 6684c5df8287109ee8d1fc7e58f0ac10a7517310b6a1586d209f39b8c768545a18.97%
- 71c182b3550a7dcc61b56c2d7e363673574cd03000a5081c0a228d775ecac1337.88%
- 2bde775d1adca83f65373fe274edd41722eff8e3b158782563e9a7d1584f08ca6.37%
- c3cc2aed40e4d945b17fc04c61aadd93579952a5bd0b394c559bf404b2fb40356.32%
- 2dfaa917a7cab5f5c37ea37b155982c5608c45a3d4f14c7b15435abbe67475546.14%
- 14709c897bb6d5beb5465ec2a2a28c970c48130ee0849ce809efefa8c4cee0522.37%
- c32cd1528cd9d3a2d6763357061a85d1e02da2209377a4ead1f4f7d7e3c1367c2.21%
- a122e7880930d06ee1c4ec0b7a5c247011434074e9bd3f4e38b20edf908b6f591.74%
Process Ancestry
Top Grandparents
- explorer.exe19.47%
- Veeam.EndPoint.Tray.exe12.69%
- kpatch.exe12.25%
- msiexec.exe6.13%
- services.exe4.38%
- sedlauncher.exe2.63%
- RuntimeBroker.exe0.66%
- chrome.exe0.22%
- cmd.exe0.22%
Top Parents
- cmd.exe80.07%
- LM.Detection_x64.exe1.25%
- setup.exe0.73%
- rundll32.exe0.55%
- ccmsetup.exe0.35%
- svchost.exe0.28%
- powershell.exe0.23%
Top Children
- DismHost.exe97.12%
- conhost.exe2.79%
- wimserv.exe0.09%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does Dism.exe normally do?
Used during Windows servicing, feature updates, and image management. Windows Update invokes DISM for feature installations and component cleanup.
When is Dism.exe suspicious?
Disabling security features (Windows Defender, firewall). Enabling legacy features (SMBv1, Telnet). Running outside of maintenance windows.
How do attackers abuse Dism.exe?
Attackers use DISM to disable Windows Defender ("dism /online /disable-feature /featurename:Windows-Defender") or enable vulnerable legacy protocols. Can also be used to install backdoor features.
Detection guidance
Monitor DISM command-line arguments for /disable-feature targeting security components. Alert on enabling of legacy/vulnerable features like SMBv1.
False positive notes
Windows Update, SCCM, and IT administration regularly use DISM for servicing.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about Dism.exe
Rocky answers questions about Dism.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.