uesFaService.exe

by ManageEngine/Zoho
Endpoint Security

Summary

UES File Activity Service - ManageEngine Endpoint DLP file activity monitoring.

uesFaService.exe is the 1248th most commonly executed Windows program in EchoTrail's dataset, observed 1,160 times across enterprise environments. It typically runs from C:\Program Files (x86)\ManageEngine\UEMS_Agent\DeviceControl\bin and it is most often launched by uesAgentService.exe.

1248th
most commonly executed Windows program
1,160
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Program Files (x86)\ManageEngine\UEMS_Agent\DeviceControl\bin100%

Top Hashes (SHA256)

  • 2030dd6594694bd726af08e0bb4f2ef9c6450bd583b3a15cf44986dc86a8fbdd100%

Process Ancestry

Top Parents

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Ask Rocky about uesFaService.exe

Rocky answers questions about uesFaService.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.