NisSrv.exe
Summary
Windows Defender Network Inspection Service - performs real-time network traffic inspection for known vulnerability exploits and malicious patterns.
NisSrv.exe is the 586th most commonly executed Windows program in EchoTrail's dataset, observed 8,284 times across enterprise environments. It typically runs from C:\ProgramData\... and it is most often launched by services.exe.
Behavior
Top Paths
- C:\ProgramData\...92.01%
- C:\Program Files\Windows Defender7.77%
- C:\Program Files\Microsoft Security Client0.22%
Top Hashes (SHA256)
- 1a6c31f6cfae5564b30fee34901da377f22dde3174bb4be0ce0c678faf77d6105.57%
- 7441b012d69115ca8084128f709ec2052c9a24e7b7f6ed54e1fa1869b44e3e034.54%
- 2e0e9650f1be1f20d106ec38aca36b35658f161e1901e412e5ae535f72f5b5db3.68%
- 7ccd14995f2a1f76c5d52d22560ba310eca926a3d3569e1f797e7a4289b963c73.36%
- 5eeb0a2b903901f3d408ea8b9baeceb9ccf341cf2933084510c3f0ba5a59d18d3.23%
- 6d7f3813f39a016301218fe0437113ceee46fecbbe044e68a6a97a70cd867f1c3.12%
- d794aba0126c332d7391a3af6dca785d1787856198d451112a2ec91ca282ecf32.79%
- 8ea604e9f8cd45190ce102884422513021caace211d04e8014e5f3d6884f41e92.77%
- 82a23ab40462390469ac72c952bd40f21b3ecd254cc7ee6118049644351aa7a22.73%
- b147e146abe9f2187f2f06798f34a312ee316d43d7cf6c0b7ea3e792e07953fe2.55%
Process Ancestry
Top Grandparents
- wininit.exe100%
Top Parents
- services.exe99.98%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does NisSrv.exe normally do?
Runs as part of Windows Defender to inspect network traffic for exploit patterns. Part of the Network Inspection System (NIS).
When is NisSrv.exe suspicious?
Not running when Defender is active. Service disabled unexpectedly.
False positive notes
Normal Windows Defender component.
Related Processes
Ask Rocky about NisSrv.exe
Rocky answers questions about NisSrv.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.