where.exe
Summary
Windows file search utility. Locates files matching a pattern in the PATH or specified directories. Used in discovery to find installed tools and executables.
where.exe is the 1441st most commonly executed Windows program in EchoTrail's dataset, observed 805 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by w3wp.exe.
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- fd9d35cae2120c38cb96d38f040737ca80e41f1fc59b1b02324efb7e091aa25591.88%
- 4dc3fa01ba87e9204ad65668a9c92f98353a0ba370bc59f61d3eafe8c754e2486.62%
- ade557dd65848c5cf6565913cf6e01cf5c9a8033f0d784c4d6932394958d743e0.88%
- 0da0911372136e3a1e78a4e118f51c7b82a6e1e71580d44daa4c529d4ecd65d80.25%
- 24db660179dfb2f36705923cf64218a8cb4f1133e63148295d5bf2219672a79e0.25%
- f949863f5e351eeb5054f04f181fe582e98cb322100956ed938538523258440c0.12%
Process Ancestry
Top Grandparents
- cmd.exe90%
- explorer.exe10%
Top Parents
- w3wp.exe87.33%
- cmd.exe12.3%
- svchost.exe0.12%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does where.exe normally do?
Runs from C:\Windows\System32. Used by administrators and scripts to find executables in the PATH. Common in build scripts and development workflows.
When is where.exe suspicious?
Searching for security tools (where python, where nmap, where mimikatz). Part of automated enumeration scripts. Searching for credentials or sensitive file types.
How do attackers abuse where.exe?
DISCOVERY: Used to locate installed tools that could be leveraged for further attack (python, curl, ssh, etc.) or to find specific file types. Low-risk individually but part of enumeration tradecraft.
Detection guidance
LOW-PRIORITY: Monitor as part of broader enumeration patterns rather than individually. DATA SOURCES: Process creation (Sysmon 1)
False positive notes
Extremely common in normal operations. Developers, scripts, and build tools use where.exe routinely.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about where.exe
Rocky answers questions about where.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.