repadmin.exe
Summary
Active Directory Replication Administration tool - diagnoses and troubleshoots AD replication between domain controllers.
repadmin.exe is the 740th most commonly executed Windows program in EchoTrail's dataset, observed 4,643 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by powershell.exe.
Behavior
Top Paths
- C:\Windows\System3299.78%
- C:\Windows\SysWOW640.22%
Top Hashes (SHA256)
- 41b4176d7bfce71e05f60943a42e9316033f2e4687566270fed648002eee3b4299.22%
- ed51f5fba2db3eb3bbd307223de31f053d5f4485095bfe8bb257b789498d74ed0.56%
- 98d3a57e68a3553f4305cc28eabaf371df679c3906618bf0a276e78f5779f6ed0.22%
Process Ancestry
Top Parents
- powershell.exe99.44%
- cmd.exe0.56%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does repadmin.exe normally do?
Used by AD administrators on domain controllers to monitor and troubleshoot replication health. Part of RSAT tools.
When is repadmin.exe suspicious?
Running on workstations (should only be on DCs or admin workstations with RSAT). Used to query replication metadata for all accounts. Running by non-AD-admin accounts.
How do attackers abuse repadmin.exe?
Attackers with domain admin access can use repadmin to gather AD replication metadata and understand the AD topology. More commonly, DCSync attacks (via mimikatz) use the same replication protocol that repadmin queries. Repadmin itself is used for AD reconnaissance.
Detection guidance
Alert on repadmin execution on non-DC systems. Monitor for repadmin /showrepl and /replsummary on workstations.
False positive notes
AD administrators regularly use repadmin on domain controllers. RSAT-equipped admin workstations may run it.
Related Processes
Ask Rocky about repadmin.exe
Rocky answers questions about repadmin.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.