esentutl.exe

by Microsoft
System UtilityLOLBinhigh risk

Summary

Extensible Storage Engine (ESE/JET) utility - manages ESE databases used by Active Directory, Exchange, and Windows components. Can copy locked database files.

esentutl.exe is the 758th most commonly executed Windows program in EchoTrail's dataset, observed 4,378 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by AXIOMProcess.exe.

758th
most commonly executed Windows program
4,378
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 753feb8e2bc07b6ed0e3ba836a33ec3c6f097a237fb9d48c23938892c8a16f4a63.03%
  • 8a0bf768502c8006ceac62e3f1564e6893595170a4601e89b0f67c574ec98c4129.6%
  • a3ee005c46f1dea44f2affd99c3bd1545b7d5448cb54cf774841cf93da5a72087.37%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does esentutl.exe normally do?

Used for ESE database maintenance (defragmentation, repair, integrity checks). Legitimately used by Exchange administrators and AD maintenance tasks.

When is esentutl.exe suspicious?

Copying ntds.dit or SAM/SYSTEM registry hives. Operating on browser credential databases. Running on workstations (typically a server admin tool).

How do attackers abuse esentutl.exe?

Attackers use "esentutl.exe /y /vss ntds.dit" to copy the locked Active Directory database for offline credential extraction. Can also copy locked browser credential databases and other ESE-format files. The /y flag copies files using raw I/O, bypassing locks.

Detection guidance

Alert on esentutl.exe accessing ntds.dit, SAM, SYSTEM, or SECURITY files. Monitor for /y flag usage on sensitive database paths. Any use on workstations should be investigated.

False positive notes

Exchange and AD administrators use esentutl for database maintenance. Check whether the user has legitimate admin responsibilities.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about esentutl.exe

Rocky answers questions about esentutl.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.