ipconfig.exe

by Microsoft
Operating Systemmedium risk

Summary

IP Configuration (ipconfig.exe) displays TCP/IP network configuration including IP addresses, subnet masks, default gateways, DNS servers, and DHCP information. Supports releasing and renewing DHCP leases and flushing DNS cache.

ipconfig.exe is the 284th most commonly executed Windows program in EchoTrail's dataset, observed 39,119 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by QualysAgent.exe.

284th
most commonly executed Windows program
39,119
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3277.71%
  • C:\Windows\SysWOW6422.27%
  • C:\Windows\WinSxS\amd64_microsoft-windows-ipconfig_31bf3856ad364e35_6.3.9600.17415_none_3d44ebe6ebac154d0.01%

Top Hashes (SHA256)

  • 21e8b9bd30650e96c36e976ae35b01e409199c244e6a5480a746692c01d78b8419.06%
  • de85261daf12e338725994ff1d4f3399cb2bcabef3960b55b842ea85fc31813217.63%
  • c5dbbddd1193c7adca1e30cd17b8c7af6a76c406dd84dc164bb959c135f1aa7016.78%
  • 5440388229f609e47c74734c78beb85d68abd1d79f3cb7a6b6596627d053d0ff11.12%
  • 87b036c720fbd5e63355b9920a2864feaf59b1584ebd8458651936ab8c7c1f819.76%
  • 5ee3fd7ca1ac876d0de539d469bfc333594fca3df9f377cc96c756d9648697f19.04%
  • 7d7d13e55b4431f42d1ff86189fb8bf27f93cfef4179271c4264a6f5a35a94f74.44%
  • 69ea4dcc47088911461ebb9adc2ba574b3e2cf46943a5c74f3bf12476bd053263%
  • 53e000f5aa9b3a00934319db8080bb99cb323bf48fc628a64f75d7847c2656062.44%
  • 7addcfb5b4f8017a4f01361852b0518067d16eeff21d90796cf6991836592f061.48%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does ipconfig.exe normally do?

Located in C:\Windows\System32 or C:\Windows\SysWOW64. Commonly launched by QualysAgent, management agents, and cmd.exe.

When is ipconfig.exe suspicious?

Part of discovery sequence with other recon tools. Spawned by unusual parents (w3wp.exe, wmiprvse.exe). Not suspicious in isolation.

How do attackers abuse ipconfig.exe?

Network configuration discovery: attackers use ipconfig /all to understand network topology, identify domain controllers (DNS servers), and find lateral movement targets.

Detection guidance

Do not alert alone. Use as component in discovery activity correlation rules.

False positive notes

Very common in monitoring agents and scripts.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about ipconfig.exe

Rocky answers questions about ipconfig.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.