utilman.exe
Summary
Windows Utility Manager / Ease of Access. Provides accessibility features (magnifier, narrator, on-screen keyboard) from the login screen. Classic persistence/backdoor target — replacing it with cmd.exe gives SYSTEM-level shell access from the login screen.
utilman.exe is the 2341st most commonly executed Windows program in EchoTrail's dataset, observed 201 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by winlogon.exe.
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 006eab15d43639b420ac7380a923230cb47d96f35a0b0377538ff49725efc23e62.37%
- 7e4aedfca93483d1c28f36b8957923da8d1b8971196c018715ef243b3d2dfabd8.6%
- 877fb7458dbe7d8adf4849c5157915d66f1ae0abe08b4787fb4369e0822456a28.06%
- b5bc4fce58403ea554691db678e6c8c448310fe59990990f0e37cd4357567d374.84%
- 5a08d6852f104da9a7a586e876bc3452e89ef556ccd031fb061b5e2bbc66c0dd3.76%
- bc805cd4495d26926171d3ac40d6730870d8c81880dbd0d4ab5f9a25b3fcebdd2.69%
- d0d556a4730e3dcb19b532e2590f0cb9c7e6c94b5a2d4c247d7c9b15bc04f0dc2.69%
- 4b4b20bb9bfcf79c2aa4edc39c649ca6244851b95b1f3842a187450d4e2bebe11.61%
- e6c9c88491ef6fb4b4dafac3276c8e2a3b2bc3c4d7825f4eaa3ac99e1801195b1.61%
- 0c044dd0ab9a389f137a74e8c46b26ac47179e703cc2d9be16d416be536fb3ea1.08%
Process Ancestry
Top Grandparents
- smss.exe89.47%
- oobeldr.exe5.26%
- svchost.exe5.26%
Top Parents
- winlogon.exe98.01%
Top Children
- sethc.exe51.72%
- osk.exe37.93%
- AtBroker.exe3.45%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does utilman.exe normally do?
Runs from C:\Windows\System32. Launched when user clicks the Ease of Access button on the login screen or presses Win+U. Opens accessibility tool selection dialog. Legitimate instances are short-lived UI processes.
When is utilman.exe suspicious?
utilman.exe replaced with another binary (file hash change). utilman.exe spawning cmd.exe, powershell.exe, or any shell. utilman.exe image path pointing to a non-System32 location. Registry modification of HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe (debugger key redirect).
How do attackers abuse utilman.exe?
1. BINARY REPLACEMENT: Attacker boots from recovery media or exploits writable System32 access to replace utilman.exe with cmd.exe. At the login screen, clicking Ease of Access launches cmd.exe as SYSTEM. No credentials required. 2. IMAGE FILE EXECUTION OPTIONS (IFEO) DEBUGGER: Set HKLM\...\IFEO\utilman.exe\Debugger to "cmd.exe" or a malicious binary. When utilman.exe is invoked, Windows launches the debugger instead, with SYSTEM privileges. 3. STICKY KEYS VARIANT: Same technique applied to sethc.exe (Sticky Keys). Often used together. This is one of the oldest and most well-known Windows persistence techniques. Still effective on systems with physical access or remote desktop access to the login screen.
Detection guidance
HIGH-CONFIDENCE DETECTIONS: - File hash change for C:\Windows\System32\utilman.exe - IFEO debugger key set for utilman.exe - utilman.exe spawning cmd.exe, powershell.exe, or any unexpected child - utilman.exe running from a path other than System32 DATA SOURCES: File integrity monitoring, registry events (Sysmon 12/13), process creation (Sysmon 1)
False positive notes
Legitimate accessibility feature use. Windows Updates may modify the binary (hash change). Some accessibility software may interact with utilman.exe.
Related Processes
Ask Rocky about utilman.exe
Rocky answers questions about utilman.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.