rasdial.exe
Summary
Windows Remote Access Service Dial utility - establishes and manages dial-up and VPN connections from the command line.
rasdial.exe is the 675th most commonly executed Windows program in EchoTrail's dataset, observed 5,955 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by powershell.exe.
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- fbaf36c2fc8c597dacbdc7976c6c541d3e8ecf2d6e8c0b302e4a95a74282416935.26%
- 31016ae60a8aef2dbf1c399f7709bc4ff69be1e2ebae5699fa55cfca606c397a33.56%
- 7427fe46c5a8b9a8e2a85ffe4af8706473ce02ecd4168517c3ff81e6802302e129.35%
- a5d1f1c9a53f285d027cd1d57326fb323c4b90fbfef9b9806a46328a09b7bf081.81%
- a7291017fd7de3e23519f93d51b747b8c124647973f476d4c352df2491cf57890.02%
Process Ancestry
Top Grandparents
- services.exe99.82%
- explorer.exe0.18%
Top Parents
- powershell.exe0.02%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does rasdial.exe normally do?
Used to programmatically connect to VPN or dial-up connections configured in Windows. Common in logon scripts.
When is rasdial.exe suspicious?
Establishing connections to unknown VPN endpoints. Credentials passed on command line. Running outside of normal logon script timing.
How do attackers abuse rasdial.exe?
Attackers can use rasdial to establish outbound VPN tunnels for command-and-control or data exfiltration. Credentials may be visible in command-line logging.
Detection guidance
Monitor for rasdial establishing connections to non-corporate VPN endpoints. Log command-line arguments to capture connection targets.
False positive notes
Corporate VPN logon scripts commonly use rasdial.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about rasdial.exe
Rocky answers questions about rasdial.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.