Dism.exe

by Microsoft
System Utilitymedium risk

Summary

Deployment Image Servicing and Management - manages Windows images, features, packages, and drivers. Can enable/disable Windows features and service offline images.

Dism.exe is the 797th most commonly executed Windows program in EchoTrail's dataset, observed 3,994 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by cmd.exe.

797th
most commonly executed Windows program
3,994
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3299.75%
  • C:\Windows\SysWOW640.15%
  • C:\Program Files (x86)\Windows Kits\Assessment and Deployment Kit\Deployment Tools\amd64\DISM0.1%

Top Hashes (SHA256)

  • 1687c9fffd9a9db09bd43ad192baedaa43b95d1c0a6a9f3d37bf4c0565fa26c622.75%
  • 2fbff06b431e9b0144bfc689e94257b77f9a8f91f03af4851bd100278415a66719.05%
  • 6684c5df8287109ee8d1fc7e58f0ac10a7517310b6a1586d209f39b8c768545a18.97%
  • 71c182b3550a7dcc61b56c2d7e363673574cd03000a5081c0a228d775ecac1337.88%
  • 2bde775d1adca83f65373fe274edd41722eff8e3b158782563e9a7d1584f08ca6.37%
  • c3cc2aed40e4d945b17fc04c61aadd93579952a5bd0b394c559bf404b2fb40356.32%
  • 2dfaa917a7cab5f5c37ea37b155982c5608c45a3d4f14c7b15435abbe67475546.14%
  • 14709c897bb6d5beb5465ec2a2a28c970c48130ee0849ce809efefa8c4cee0522.37%
  • c32cd1528cd9d3a2d6763357061a85d1e02da2209377a4ead1f4f7d7e3c1367c2.21%
  • a122e7880930d06ee1c4ec0b7a5c247011434074e9bd3f4e38b20edf908b6f591.74%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does Dism.exe normally do?

Used during Windows servicing, feature updates, and image management. Windows Update invokes DISM for feature installations and component cleanup.

When is Dism.exe suspicious?

Disabling security features (Windows Defender, firewall). Enabling legacy features (SMBv1, Telnet). Running outside of maintenance windows.

How do attackers abuse Dism.exe?

Attackers use DISM to disable Windows Defender ("dism /online /disable-feature /featurename:Windows-Defender") or enable vulnerable legacy protocols. Can also be used to install backdoor features.

Detection guidance

Monitor DISM command-line arguments for /disable-feature targeting security components. Alert on enabling of legacy/vulnerable features like SMBv1.

False positive notes

Windows Update, SCCM, and IT administration regularly use DISM for servicing.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about Dism.exe

Rocky answers questions about Dism.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.