sdclt.exe
Summary
Windows Backup and Restore control panel applet - manages Windows backup settings and restore operations.
sdclt.exe is the 1129th most commonly executed Windows program in EchoTrail's dataset, observed 1,525 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 61bd24487c389fc2b939ce000721677cc173bde0edcafccff81069bbd9987bfd100%
Process Ancestry
Top Grandparents
- wininit.exe100%
Top Parents
- services.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does sdclt.exe normally do?
Launched from Control Panel or Settings to configure Windows Backup. Auto-elevates without a UAC prompt on some Windows versions.
When is sdclt.exe suspicious?
Spawning unexpected child processes. Being used as a UAC bypass vector. Running from command line rather than GUI.
How do attackers abuse sdclt.exe?
sdclt.exe auto-elevates on Windows 10 and can be exploited for UAC bypass. Attackers modify the HKCU registry to hijack the elevated process and execute arbitrary commands with high integrity. Multiple UAC bypass techniques documented.
Detection guidance
Monitor for sdclt.exe spawning unexpected child processes (cmd.exe, powershell.exe). Alert on registry modifications to HKCU\Software\Classes\exefile\shell or related keys before sdclt.exe execution.
False positive notes
Legitimate when users access Backup and Restore from Control Panel.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about sdclt.exe
Rocky answers questions about sdclt.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.