find.exe
Summary
Find (find.exe) is a built-in Windows command-line utility that searches for text strings within files or piped output. It is the Windows equivalent of the Unix grep command for simple string matching. Commonly used in scripts to filter command output.
find.exe is the 2nd most commonly executed Windows program in EchoTrail's dataset, observed 43,411,478 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by cmd.exe.
Behavior
Top Paths
- C:\Windows\System32100%
- C:\Windows\SysWOW64<0.01%
- C:\...<0.01%
- C:\Users\...<0.01%
Top Hashes (SHA256)
- 794b46b2613cb208760e69ea964a649d28fe9acd68110bec08a5ca557014b68a52.72%
- ffbd63d8e677610ec22481d2bcd46ad231ef9db2cd9d599de97a51d4ec18477117.03%
- af83f87cf95cc01d4ffb86a8cad8c11fe1581f64098681c68390cf2f4e64202d10.8%
- 1a1876c5eed2b8cd9e14ebff3f4eeb7e21552a4c6aab4bf392a55f8df3612dab10.38%
- 40c0ec6d7371d316bc1f0abe80d0236f613c9fb88dce2d9b5d5fd4a1a59e8b492.85%
- 9511d0a34d77da73c10b648cd5a832fe914c9eb37b5e4a391f5ae2399f0994252.15%
- 935b69e0e98f3fcd8603e615eeaef6a64582f30334b14394bd7e57578f30fdc02.07%
- 3796ecbf04e6a1162078ad914ac76cc41761166574b7a2f5e07e5e0d1e80d3dd1.83%
- c77135ac8ffbf6bdfe71331c3d014b924d0e167608779d385823aa203bdd56360.11%
- a3d85036bcb0b3b50691e02d1952821e7b943680d8f8e4cc16613d2c72f44e6c0.04%
Process Ancestry
Top Grandparents
- LTSVC.exe99.99%
- svchost.exe<0.01%
- explorer.exe<0.01%
- Asusgiftbox.exe<0.01%
- cmd.exe<0.01%
- bash.exe<0.01%
- PDQDeployRunner-1.exe<0.01%
- MsSense.exe<0.01%
- cscript.exe<0.01%
- services.exe<0.01%
Top Parents
- cmd.exe100%
- powershell_ise.exe<0.01%
- bash.exe<0.01%
- find.exe<0.01%
- conhost.exe<0.01%
- backgroundTaskHost.exe<0.01%
- SenseCncProxy.exe<0.01%
- NETSTAT.EXE<0.01%
- SAAZJobDownload.exe<0.01%
- powershell.exe<0.01%
Top Children
- find.exe33.71%
- conhost.exe25.84%
- grep.exe5.62%
- NETSTAT.EXE5.62%
- powershell.exe4.49%
- WMIC.exe2.25%
- cmd.exe1.12%
- sc.exe1.12%
- ShoretelRegistry.exe1.12%
- task.exe1.12%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does find.exe normally do?
Located in C:\Windows\System32. Almost exclusively launched by cmd.exe (99.99% of executions in this dataset). The high execution count reflects its use in piped commands (e.g., netstat | find "ESTABLISHED", tasklist | find "process"). Very rarely has child processes.
When is find.exe suspicious?
find.exe alone is almost never suspicious. In context, it is part of discovery/enumeration chains: netstat | find, tasklist | find, sc query | find. These chains are common in both administration and attack reconnaissance. Focus on the parent command chain rather than find.exe itself.
How do attackers abuse find.exe?
Not directly abused. Used as a supporting tool in reconnaissance command chains during the discovery phase of attacks. Attackers use it to filter output of network, process, and service enumeration commands to find specific targets.
Detection guidance
Do not create detections for find.exe in isolation. Instead, detect the parent command chains that include find.exe as part of enumeration activity (e.g., cmd.exe running netstat piped to find, or tasklist piped to find). These patterns are useful as components of broader correlation rules for discovery activity.
False positive notes
Extremely common in legitimate scripts and administration. Management agents run piped find commands routinely. The overwhelming majority of find.exe executions are benign. Alert on the broader pattern (who is running the reconnaissance chain and why) rather than the individual tool.
Related Processes
Ask Rocky about find.exe
Rocky answers questions about find.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.