splunk-powershell.exe

by Splunk
Endpoint Security

Summary

Splunk PowerShell module process. Executes PowerShell-based data collection scripts for the Splunk Universal Forwarder, collecting Windows event logs, performance data, and other telemetry.

splunk-powershell.exe is the 177th most commonly executed Windows program in EchoTrail's dataset, observed 87,246 times across enterprise environments. It typically runs from C:\Program Files\Splunk\bin and it is most often launched by splunkd.exe.

177th
most commonly executed Windows program
87,246
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Program Files\Splunk\bin75.57%
  • C:\Program Files\SUFwd\bin22.87%
  • C:\Program Files\SplunkUniversalForwarder\bin1.56%

Top Hashes (SHA256)

  • 950dff45af9486ef9a6a8926be0150c733d1ecfaa501370c9ee7495e73827dab93.62%
  • f9d7ca4f228a5a7cde420f872a183be91ed60fcc25c5fb9540c36df4a92654346.38%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does splunk-powershell.exe normally do?

Part of Splunk Universal Forwarder installation. Runs PowerShell collection scripts.

When is splunk-powershell.exe suspicious?

Running from outside Splunk installation directories.

How do attackers abuse splunk-powershell.exe?

Not directly abused.

Detection guidance

No detection needed. Presence indicates Splunk forwarder deployment.

False positive notes

Normal Splunk operation.

Related Processes

Ask Rocky about splunk-powershell.exe

Rocky answers questions about splunk-powershell.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.