gpupdate.exe
Summary
Group Policy Update (gpupdate.exe) forces an immediate refresh of local and Active Directory Group Policy settings. It applies both computer and user policy updates from the domain controller.
gpupdate.exe is the 59th most commonly executed Windows program in EchoTrail's dataset, observed 581,771 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by svchost.exe.
Behavior
Top Paths
- C:\Windows\System32100%
- C:\Windows\SysWOW64<0.01%
Top Hashes (SHA256)
- dfd0b48a8ff2c11694eea3441a663f2ca578160ea2c58f8158722da2536a451637.87%
- b76ce2bba63bd2949fa6e36fba963379b9d682f7642cd3782d9818fcd30a3e0023.17%
- 820995f970282b86c151b8e965d725aa1f0357906aed65fdf08e0ec6ae3f5f5712.23%
- fe428f64b6920cbd542bf7097f009a576673888967cb5ae8803d310667ed428d8.43%
- b7a3e15d0963d76907602b65c736745d424b6977d4d91fb9b55373f01e8a72f44.66%
- 3dd84330921869c8980fef735a32391f15c2fa0edca1a68e82eee48bdac1b2273.84%
- ec8e52bab421a42dc3c17837d3a7c519f034d8d03a62136b57c0989e2256d4f82.42%
- 91ffab6770bcf42f25b8674fe8c0df039d31b15d6a84616dfe839786f90889312.19%
- 14803cb04d08ad97c194a587273545627e729acc747669a0f6f069e0655e24382.19%
- f1d24a99a27a4a485909ecad320e881c14c418a77d175bf666991d9709fef8511.11%
Process Ancestry
Top Grandparents
- services.exe99.95%
- explorer.exe0.05%
- LTSVC.exe<0.01%
- RuntimeBroker.exe<0.01%
- svchost.exe<0.01%
- Windows10Upgrade.exe<0.01%
Top Parents
- svchost.exe91.12%
- powershell.exe8.84%
- cmd.exe0.03%
- Windows10UpgraderApp.exe<0.01%
- devctrlaction64.exe<0.01%
- pwsh.exe<0.01%
- RuntimeBroker.exe<0.01%
Top Children
- conhost.exe100%
- WerFault.exe<0.01%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does gpupdate.exe normally do?
Located in C:\Windows\System32. Predominantly launched by svchost.exe (scheduled Group Policy refresh, typically every 90 minutes) and by powershell.exe (admin-initiated gpupdate /force). Spawns conhost.exe.
When is gpupdate.exe suspicious?
Generally not suspicious. Could be used as part of a GPO-based attack to force immediate application of a malicious Group Policy Object, but gpupdate itself is just the refresh mechanism.
How do attackers abuse gpupdate.exe?
Not directly abused. If an attacker has domain admin privileges and has planted a malicious GPO, they might use gpupdate /force on target machines to accelerate the application of their malicious policy. The attack vector is the GPO, not gpupdate.
Detection guidance
Low priority for gpupdate itself. Focus on detecting malicious GPO modifications via Event ID 5136 (Directory Service Changes) and monitoring for suspicious GPO content (scripts, software installation policies from unexpected sources).
False positive notes
Very common — automatic GPO refresh runs every 90 minutes on domain-joined machines. Administrators frequently run gpupdate /force after policy changes. PowerShell-initiated gpupdate is normal for admin workflows.
Related Processes
Ask Rocky about gpupdate.exe
Rocky answers questions about gpupdate.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.