platform-scripting-plugin.exe
Summary
Endpoint management platform plugin. Collects system state, handles patching, or manages security components depending on the plugin type.
platform-scripting-plugin.exe is the 152nd most commonly executed Windows program in EchoTrail's dataset, observed 109,825 times across enterprise environments. It typically runs from C:\Program Files (x86)\ITSPlatform\plugin\scripting and it is most often launched by platform-agent-core.exe.
Behavior
Top Paths
- C:\Program Files (x86)\ITSPlatform\plugin\scripting100%
Top Hashes (SHA256)
- 1002fb752d7c39cd018f745e93d1ee2ba6adad937d07a97d4f82131aff679b9827.08%
- abdc9afce76fe71028844ed8fd5d667039b90db7b79fde0d0e907b86aaf7a46114.13%
- 02bbebeb160c822cf468b7a14a0806dbb910243a10d182cf5543b0476912532013.9%
- 77b537e0e755a666c4e38a60500021effd4c20bb0da3cda3f527f55995334cad13.65%
- 37e912827171a08fa806921f3d028456f740c5d9f842a4ac495958db1c67bc6313.14%
- 8eb51e6aaf296e16db970b19f3340fce12dc50f3a8a7183441492f910dd795747.02%
- b2a13aba111a9118008f430c59f4c9b3eeee2d63d2792a402dcc295bda3aa5065.83%
- d489bc504fcc18a3a7d73eac7fecad74bf12277de0cc2eb33bf495b41ec8c6b15.25%
Process Ancestry
Top Parents
- platform-agent-core.exe96.34%
Top Children
- powershell.exe66.68%
- conhost.exe33.32%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does platform-scripting-plugin.exe normally do?
Part of an endpoint management agent. Runs continuously.
When is platform-scripting-plugin.exe suspicious?
Running from unexpected paths.
How do attackers abuse platform-scripting-plugin.exe?
Not commonly abused.
Detection guidance
No detection needed.
False positive notes
Normal management agent operation.
Related Processes
Ask Rocky about platform-scripting-plugin.exe
Rocky answers questions about platform-scripting-plugin.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.