utilman.exe

by Microsoft
Operating Systemhigh risk

Summary

Windows Utility Manager / Ease of Access. Provides accessibility features (magnifier, narrator, on-screen keyboard) from the login screen. Classic persistence/backdoor target — replacing it with cmd.exe gives SYSTEM-level shell access from the login screen.

utilman.exe is the 2341st most commonly executed Windows program in EchoTrail's dataset, observed 201 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by winlogon.exe.

2341st
most commonly executed Windows program
201
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 006eab15d43639b420ac7380a923230cb47d96f35a0b0377538ff49725efc23e62.37%
  • 7e4aedfca93483d1c28f36b8957923da8d1b8971196c018715ef243b3d2dfabd8.6%
  • 877fb7458dbe7d8adf4849c5157915d66f1ae0abe08b4787fb4369e0822456a28.06%
  • b5bc4fce58403ea554691db678e6c8c448310fe59990990f0e37cd4357567d374.84%
  • 5a08d6852f104da9a7a586e876bc3452e89ef556ccd031fb061b5e2bbc66c0dd3.76%
  • bc805cd4495d26926171d3ac40d6730870d8c81880dbd0d4ab5f9a25b3fcebdd2.69%
  • d0d556a4730e3dcb19b532e2590f0cb9c7e6c94b5a2d4c247d7c9b15bc04f0dc2.69%
  • 4b4b20bb9bfcf79c2aa4edc39c649ca6244851b95b1f3842a187450d4e2bebe11.61%
  • e6c9c88491ef6fb4b4dafac3276c8e2a3b2bc3c4d7825f4eaa3ac99e1801195b1.61%
  • 0c044dd0ab9a389f137a74e8c46b26ac47179e703cc2d9be16d416be536fb3ea1.08%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does utilman.exe normally do?

Runs from C:\Windows\System32. Launched when user clicks the Ease of Access button on the login screen or presses Win+U. Opens accessibility tool selection dialog. Legitimate instances are short-lived UI processes.

When is utilman.exe suspicious?

utilman.exe replaced with another binary (file hash change). utilman.exe spawning cmd.exe, powershell.exe, or any shell. utilman.exe image path pointing to a non-System32 location. Registry modification of HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe (debugger key redirect).

How do attackers abuse utilman.exe?

1. BINARY REPLACEMENT: Attacker boots from recovery media or exploits writable System32 access to replace utilman.exe with cmd.exe. At the login screen, clicking Ease of Access launches cmd.exe as SYSTEM. No credentials required. 2. IMAGE FILE EXECUTION OPTIONS (IFEO) DEBUGGER: Set HKLM\...\IFEO\utilman.exe\Debugger to "cmd.exe" or a malicious binary. When utilman.exe is invoked, Windows launches the debugger instead, with SYSTEM privileges. 3. STICKY KEYS VARIANT: Same technique applied to sethc.exe (Sticky Keys). Often used together. This is one of the oldest and most well-known Windows persistence techniques. Still effective on systems with physical access or remote desktop access to the login screen.

Detection guidance

HIGH-CONFIDENCE DETECTIONS: - File hash change for C:\Windows\System32\utilman.exe - IFEO debugger key set for utilman.exe - utilman.exe spawning cmd.exe, powershell.exe, or any unexpected child - utilman.exe running from a path other than System32 DATA SOURCES: File integrity monitoring, registry events (Sysmon 12/13), process creation (Sysmon 1)

False positive notes

Legitimate accessibility feature use. Windows Updates may modify the binary (hash change). Some accessibility software may interact with utilman.exe.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about utilman.exe

Rocky answers questions about utilman.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.