powercfg.exe
Summary
Power Configuration (powercfg.exe) is a command-line tool for managing Windows power settings, power plans, sleep/hibernate configuration, and energy reporting.
powercfg.exe is the 121st most commonly executed Windows program in EchoTrail's dataset, observed 177,200 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by LTSVC.exe.
Behavior
Top Paths
- C:\Windows\System3299.62%
- C:\Windows\SysWOW640.38%
Top Hashes (SHA256)
- 54b792595c594899cc17f466bb8ca9d40ff4389d54be698aab3ffe079cb7d79367.38%
- 11bba9a1dce1d749e4ff289935eb3966d9b95bd5737d65f8a256ac01494ed44415.69%
- 4c1b9be18f15309fb1686d4d8e680543a4aabeb7b8e4583218f370f2cd8b776c7.43%
- 34808b32dae08fb92de643f86931c3f06c39bf3ddcf1a88eb0fe2daf7f112cb03.91%
- 12279d4d2d7f80562f79d4dbcb7b63428e924c30a5e95f45cb0d08001a9cbddc2.48%
- 47aff914c23aec95c5bbf174a88d9880c2e9ff3c0492676a3aba41ad022bc28f2.44%
- a78cf2dc3296c773ee5ae9a4114e9bfde6135a33245c28e6bef384b4f2b797110.26%
- cb2459971a56cee45a30346281ff3b0eccea0c2bee1ae6b8477712404d2e6ae10.16%
- da5de3cdfe698b4d8d37ff10ec4826274010df8839e31aa294a0fa87230c9efd0.12%
- 383184676e88b18307a343c1bbdeff938aede45ab8acb5dfc4c8259153d452f30.11%
Process Ancestry
Top Grandparents
- services.exe84.33%
- remsh.exe13.55%
- sedlauncher.exe1.56%
- cmd.exe0.33%
- sedsvc.exe0.06%
- wininit.exe0.02%
- explorer.exe<0.01%
- firefox.exe<0.01%
- svchost.exe<0.01%
Top Parents
- LTSVC.exe86.76%
- cmd.exe12.75%
- DiskTrace.exe0.26%
- WmiPrvSE.exe0.09%
- powershell.exe0.07%
- services.exe0.04%
- AvastSvc.exe0.01%
- OLicenseHeartbeat.exe<0.01%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does powercfg.exe normally do?
Located in C:\Windows\System32. In this dataset, predominantly launched by LTSVC.exe (LabTech agent querying power configuration) and cmd.exe. Spawns conhost.exe.
When is powercfg.exe suspicious?
Generally not suspicious. Disabling hibernate (powercfg /h off) or sleep can be part of persistence mechanisms. In context with other system configuration changes, may indicate an attacker establishing a foothold.
How do attackers abuse powercfg.exe?
Minimal direct abuse. Attackers may disable sleep/hibernate to prevent a compromised system from going idle. Part of some ransomware preparation sequences that disable sleep before encryption.
Detection guidance
Low priority. powercfg /h off in combination with other suspicious activity may be a supporting indicator.
False positive notes
Management agents (LabTech) query power settings routinely. IT administrators configure power plans via powercfg. Very common in enterprise environments.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about powercfg.exe
Rocky answers questions about powercfg.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.