fsutil.exe
Summary
Windows File System Utility - performs advanced file system operations including quota management, reparse points, USN journal queries, and sparse file management.
fsutil.exe is the 963rd most commonly executed Windows program in EchoTrail's dataset, observed 2,329 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by SRFeature.exe.
Behavior
Top Paths
- C:\Windows\SysWOW6495.88%
- C:\Windows\System324.12%
Top Hashes (SHA256)
- 663176115ad56014efc43b792aead9658c3d1045cc64fe794c3ef9d4105a8f3a90.57%
- 3b13a67dd25962bb50ab60aca722b0aec4810c9c23f2f8d6e3648ad6d694b1942.78%
- c302730b6088c6e28d1d9692d4d7d512c622979e58a1f6ccec396ac1231f3de21.65%
- e9d78e39bfd9395798cc85c583ad15b0b107e17f81f3ec24b5f1bbf4ace92e141.48%
- d911c86f32f1b14f9371a0a87b57d78a97b2a9971fd15fcf562957cdc5f81d640.91%
- ec750391d52bba76bb5bbb2ff6fd53eef03b043bc48da72bac0b9c07cd0241be0.65%
- 1a988d562a72325c0e97e4be05fb311e052e12a095387754fed02b446b032a1a0.39%
- 7e791acbaa84d2d9e73c0c9dbf5e225e9b69b25d5b9af598f7802cd56f4ab01b0.39%
- 3fed60dcbc09f02746ca8789dc02748276c182901b2342c1169b6e99a55f79390.35%
- ac33f16c91283124276c3f14c9570086388999311749503af4ac55d85a15dc300.13%
Process Ancestry
Top Grandparents
- cmd.exe41.46%
- devenv.exe20.73%
- services.exe10.98%
- SRManager.exe7.32%
- explorer.exe6.1%
- vs_installer.exe6.1%
- msiexec.exe2.44%
- Unity Hub.exe2.44%
Top Parents
- SRFeature.exe85.46%
- cmd.exe3.86%
- python.exe0.34%
- SRManager.exe0.04%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does fsutil.exe normally do?
Used by administrators for file system troubleshooting, quota management, and USN journal operations.
When is fsutil.exe suspicious?
Querying USN journal (file access forensics evasion). Creating very large sparse files (disk fill attacks). Querying volume information for recon. Deleting USN journal to cover tracks.
How do attackers abuse fsutil.exe?
Attackers use "fsutil usn deletejournal" to clear the USN change journal, destroying forensic evidence of file system changes. "fsutil volume diskfree" is used for system reconnaissance.
Detection guidance
Alert on USN journal deletion. Monitor for fsutil usn and fsutil volume commands. These are unusual on workstations.
False positive notes
Storage administrators and backup tools may use fsutil for quota and volume management.
Related Processes
Ask Rocky about fsutil.exe
Rocky answers questions about fsutil.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.