rasdial.exe

by Microsoft
System Utilitymedium risk

Summary

Windows Remote Access Service Dial utility - establishes and manages dial-up and VPN connections from the command line.

rasdial.exe is the 675th most commonly executed Windows program in EchoTrail's dataset, observed 5,955 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by powershell.exe.

675th
most commonly executed Windows program
5,955
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • fbaf36c2fc8c597dacbdc7976c6c541d3e8ecf2d6e8c0b302e4a95a74282416935.26%
  • 31016ae60a8aef2dbf1c399f7709bc4ff69be1e2ebae5699fa55cfca606c397a33.56%
  • 7427fe46c5a8b9a8e2a85ffe4af8706473ce02ecd4168517c3ff81e6802302e129.35%
  • a5d1f1c9a53f285d027cd1d57326fb323c4b90fbfef9b9806a46328a09b7bf081.81%
  • a7291017fd7de3e23519f93d51b747b8c124647973f476d4c352df2491cf57890.02%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does rasdial.exe normally do?

Used to programmatically connect to VPN or dial-up connections configured in Windows. Common in logon scripts.

When is rasdial.exe suspicious?

Establishing connections to unknown VPN endpoints. Credentials passed on command line. Running outside of normal logon script timing.

How do attackers abuse rasdial.exe?

Attackers can use rasdial to establish outbound VPN tunnels for command-and-control or data exfiltration. Credentials may be visible in command-line logging.

Detection guidance

Monitor for rasdial establishing connections to non-corporate VPN endpoints. Log command-line arguments to capture connection targets.

False positive notes

Corporate VPN logon scripts commonly use rasdial.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about rasdial.exe

Rocky answers questions about rasdial.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.