gpupdate.exe

by Microsoft
Operating System

Summary

Group Policy Update (gpupdate.exe) forces an immediate refresh of local and Active Directory Group Policy settings. It applies both computer and user policy updates from the domain controller.

gpupdate.exe is the 59th most commonly executed Windows program in EchoTrail's dataset, observed 581,771 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by svchost.exe.

59th
most commonly executed Windows program
581,771
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Windows\System32100%
  • C:\Windows\SysWOW64<0.01%

Top Hashes (SHA256)

  • dfd0b48a8ff2c11694eea3441a663f2ca578160ea2c58f8158722da2536a451637.87%
  • b76ce2bba63bd2949fa6e36fba963379b9d682f7642cd3782d9818fcd30a3e0023.17%
  • 820995f970282b86c151b8e965d725aa1f0357906aed65fdf08e0ec6ae3f5f5712.23%
  • fe428f64b6920cbd542bf7097f009a576673888967cb5ae8803d310667ed428d8.43%
  • b7a3e15d0963d76907602b65c736745d424b6977d4d91fb9b55373f01e8a72f44.66%
  • 3dd84330921869c8980fef735a32391f15c2fa0edca1a68e82eee48bdac1b2273.84%
  • ec8e52bab421a42dc3c17837d3a7c519f034d8d03a62136b57c0989e2256d4f82.42%
  • 91ffab6770bcf42f25b8674fe8c0df039d31b15d6a84616dfe839786f90889312.19%
  • 14803cb04d08ad97c194a587273545627e729acc747669a0f6f069e0655e24382.19%
  • f1d24a99a27a4a485909ecad320e881c14c418a77d175bf666991d9709fef8511.11%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does gpupdate.exe normally do?

Located in C:\Windows\System32. Predominantly launched by svchost.exe (scheduled Group Policy refresh, typically every 90 minutes) and by powershell.exe (admin-initiated gpupdate /force). Spawns conhost.exe.

When is gpupdate.exe suspicious?

Generally not suspicious. Could be used as part of a GPO-based attack to force immediate application of a malicious Group Policy Object, but gpupdate itself is just the refresh mechanism.

How do attackers abuse gpupdate.exe?

Not directly abused. If an attacker has domain admin privileges and has planted a malicious GPO, they might use gpupdate /force on target machines to accelerate the application of their malicious policy. The attack vector is the GPO, not gpupdate.

Detection guidance

Low priority for gpupdate itself. Focus on detecting malicious GPO modifications via Event ID 5136 (Directory Service Changes) and monitoring for suspicious GPO content (scripts, software installation policies from unexpected sources).

False positive notes

Very common — automatic GPO refresh runs every 90 minutes on domain-joined machines. Administrators frequently run gpupdate /force after policy changes. PowerShell-initiated gpupdate is normal for admin workflows.

Related Processes

Ask Rocky about gpupdate.exe

Rocky answers questions about gpupdate.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.