powercfg.exe

by Microsoft
Operating System

Summary

Power Configuration (powercfg.exe) is a command-line tool for managing Windows power settings, power plans, sleep/hibernate configuration, and energy reporting.

powercfg.exe is the 121st most commonly executed Windows program in EchoTrail's dataset, observed 177,200 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by LTSVC.exe.

121st
most commonly executed Windows program
177,200
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3299.62%
  • C:\Windows\SysWOW640.38%

Top Hashes (SHA256)

  • 54b792595c594899cc17f466bb8ca9d40ff4389d54be698aab3ffe079cb7d79367.38%
  • 11bba9a1dce1d749e4ff289935eb3966d9b95bd5737d65f8a256ac01494ed44415.69%
  • 4c1b9be18f15309fb1686d4d8e680543a4aabeb7b8e4583218f370f2cd8b776c7.43%
  • 34808b32dae08fb92de643f86931c3f06c39bf3ddcf1a88eb0fe2daf7f112cb03.91%
  • 12279d4d2d7f80562f79d4dbcb7b63428e924c30a5e95f45cb0d08001a9cbddc2.48%
  • 47aff914c23aec95c5bbf174a88d9880c2e9ff3c0492676a3aba41ad022bc28f2.44%
  • a78cf2dc3296c773ee5ae9a4114e9bfde6135a33245c28e6bef384b4f2b797110.26%
  • cb2459971a56cee45a30346281ff3b0eccea0c2bee1ae6b8477712404d2e6ae10.16%
  • da5de3cdfe698b4d8d37ff10ec4826274010df8839e31aa294a0fa87230c9efd0.12%
  • 383184676e88b18307a343c1bbdeff938aede45ab8acb5dfc4c8259153d452f30.11%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does powercfg.exe normally do?

Located in C:\Windows\System32. In this dataset, predominantly launched by LTSVC.exe (LabTech agent querying power configuration) and cmd.exe. Spawns conhost.exe.

When is powercfg.exe suspicious?

Generally not suspicious. Disabling hibernate (powercfg /h off) or sleep can be part of persistence mechanisms. In context with other system configuration changes, may indicate an attacker establishing a foothold.

How do attackers abuse powercfg.exe?

Minimal direct abuse. Attackers may disable sleep/hibernate to prevent a compromised system from going idle. Part of some ransomware preparation sequences that disable sleep before encryption.

Detection guidance

Low priority. powercfg /h off in combination with other suspicious activity may be a supporting indicator.

False positive notes

Management agents (LabTech) query power settings routinely. IT administrators configure power plans via powercfg. Very common in enterprise environments.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about powercfg.exe

Rocky answers questions about powercfg.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.