sdclt.exe

by Microsoft
System UtilityLOLBinhigh risk

Summary

Windows Backup and Restore control panel applet - manages Windows backup settings and restore operations.

sdclt.exe is the 1129th most commonly executed Windows program in EchoTrail's dataset, observed 1,525 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.

1129th
most commonly executed Windows program
1,525
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 61bd24487c389fc2b939ce000721677cc173bde0edcafccff81069bbd9987bfd100%

Process Ancestry

Top Grandparents

Top Parents

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does sdclt.exe normally do?

Launched from Control Panel or Settings to configure Windows Backup. Auto-elevates without a UAC prompt on some Windows versions.

When is sdclt.exe suspicious?

Spawning unexpected child processes. Being used as a UAC bypass vector. Running from command line rather than GUI.

How do attackers abuse sdclt.exe?

sdclt.exe auto-elevates on Windows 10 and can be exploited for UAC bypass. Attackers modify the HKCU registry to hijack the elevated process and execute arbitrary commands with high integrity. Multiple UAC bypass techniques documented.

Detection guidance

Monitor for sdclt.exe spawning unexpected child processes (cmd.exe, powershell.exe). Alert on registry modifications to HKCU\Software\Classes\exefile\shell or related keys before sdclt.exe execution.

False positive notes

Legitimate when users access Backup and Restore from Control Panel.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about sdclt.exe

Rocky answers questions about sdclt.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.