quser.exe
Summary
Query User (quser.exe) displays information about user sessions on a Remote Desktop Session Host server or local machine. It shows logged-on users, session names, session IDs, session state, idle time, and logon time.
quser.exe is the 14th most commonly executed Windows program in EchoTrail's dataset, observed 4,948,346 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by LTSVC.exe.
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 50557fd5ad11afb07926d1fc5e84de247183a0ebc184f5d02b142db126d90fb875.62%
- 67d4ff2489b1c4e78928ca9ac9c1a79782a30bb976dc1ae49ac667cd5ac344a89.82%
- 766c791edfa6eeeba0f99d6481bfe23bf59e6acb81a930b71f3aa33efbafe5449.69%
- 84f53f3f001d06a6e74e185be9d6f943db4344e47f8a4ef8702c35aeb8703fa03.69%
- 69d5fcc7ad1f3ec8f8bae99d61672ff9cc46e3819a77981660ee50c56e526eaf0.75%
- d93f1b0a06fe6426871fd0b07f80512e984fedd5c9a1397c39509a94ffa4a57e0.32%
- 1e6e72caa1950857a7771d3aa6131264214d12cdb1587c0a89d2f6d010db251e0.11%
- 363d202d3c269dee639dc437b5d190b4ff8ecbb3807b70dfdfe08d7355976fa3<0.01%
Process Ancestry
Top Grandparents
- services.exe100%
- wsmprovhost.exe<0.01%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does quser.exe normally do?
Located in C:\Windows\System32. In this dataset, almost exclusively launched by LTSVC.exe (LabTech/ConnectWise management agent) for session monitoring. Also occasionally launched by query.exe or cmd.exe. Spawns conhost.exe.
When is quser.exe suspicious?
When used as part of a manual discovery sequence alongside whoami, net user, net group, qwinsta — indicates user enumeration. Spawned by unusual parents (wmiprvse.exe, w3wp.exe) suggesting remote execution. Not typically suspicious in isolation due to its heavy use by management agents.
How do attackers abuse quser.exe?
User discovery: attackers use quser to identify logged-on users and active sessions, particularly on RDP servers. Helps identify target accounts for credential theft or session hijacking. Part of common discovery scripts during post-exploitation.
Detection guidance
Do not alert on quser.exe alone — management agents make this too noisy. Medium-confidence: quser as part of a reconnaissance sequence with other user/session discovery commands from the same parent process. Correlate with parent process to distinguish agent automation from interactive attacker activity.
False positive notes
LabTech/ConnectWise (LTSVC.exe) accounts for the vast majority of quser executions in this dataset. Many RMM tools monitor user sessions via quser. System administrators routinely use quser on RDP servers.
Related Processes
Ask Rocky about quser.exe
Rocky answers questions about quser.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.