mountvol.exe

by Microsoft
System Utility

Summary

Volume Mount Point manager. Creates, lists, or removes volume mount points. Can expose hidden volumes or access volumes without drive letters assigned.

mountvol.exe is the 1572nd most commonly executed Windows program in EchoTrail's dataset, observed 613 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by Snagit32.exe.

1572nd
most commonly executed Windows program
613
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3288.25%
  • C:\Windows\SysWOW6411.75%

Top Hashes (SHA256)

  • caf29650446db3842e1c1e8e5e1bafadaf90fc82c5c37b9e2c75a089b747613148.11%
  • 7db6a524b2070a9bcb96062323f2f4424fbcf406e479f237cb96ede03e42307938.1%
  • 1031661048c6ef1cd70b29470d9b012c6f18c6e2d81bc7e8862f6c2223c0e0bb4.6%
  • c10d0b4ced9c19e4c6a73be211db4bc0ee9aff33b72aa2c90f38d1ebd9b197093.12%
  • 1f649f2b822a87b6c54524e20975946df0f8081ca1325cf781a9e50c66801f6b2.63%
  • 83a39941991e31834991558b4a6f4b482ad806c4707406dfbf5ef274f8cc6d991.81%
  • f247be88f22b07a36f4b71707ed7a96bd989bad37a7500da03b81709749ded7e1.31%
  • 4ebeffcf6a8be337857f48b8b6cc6a96483889cee98857c475f138e59b1dd9ca0.33%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does mountvol.exe normally do?

Runs from C:\Windows\System32. Used during disk management to create mount points for volumes without drive letters. Admin-only operation.

When is mountvol.exe suspicious?

Mounting hidden or recovery partitions. Execution by non-admin users. Used in combination with data collection tools.

How do attackers abuse mountvol.exe?

DIRECT VOLUME ACCESS: mountvol can expose volumes that don't have drive letters, including recovery partitions or hidden volumes that may contain sensitive data or backup credentials.

Detection guidance

LOW-PRIORITY: Monitor for unusual mount point creation. DATA SOURCES: Process creation (Sysmon 1)

False positive notes

Disk management operations, storage configuration, and backup tools legitimately use mountvol.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about mountvol.exe

Rocky answers questions about mountvol.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.