wininit.exe

by Microsoft
Operating Systemcritical risk

Summary

Windows Start-Up Application - initializes Session 0 during boot. Launches services.exe, lsass.exe, and lsm.exe.

wininit.exe is the 507th most commonly executed Windows program in EchoTrail's dataset, observed 11,195 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by smss.exe.

507th
most commonly executed Windows program
11,195
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 9961f4f459769b024ce26ada1054f0c0f3f567e7b5e67f614e7fca86efcde83431.64%
  • 6f3304f91e1597435d5a74edc928bbee5ebfc88cd5a650a6dac50f919137a11c12.84%
  • d5e122606054fa0b03db3ee8cf9ea7701e523875e2bdb87581ad7232ffc9308e8.45%
  • a283a3000e631e281ec3b9f2a029faaf76aaf267bb8b1921fb2b9b0b51c87d197.25%
  • 86041cb454fcc11d46764e2587815f64377f72e5df969ebb35f852b5da5bff057.01%
  • c4e98f07170cec69cacdd5cedb8927e48a2a299cb1b8cda87526e768af6174f05.38%
  • 13ad43ee6d19dfc9709c3106d796bc3f21791a564e443d042a5aa117f26806494.57%
  • 71dd6bfc68e6a840bc935ac08dc71618043bf705849b619d31a2b83e54670a3e2.72%
  • 3d5a4e21debab78e167047462a82de535cb0caa09e8232e34f0f592ffb28b5512.06%
  • 2ef3fb620bfd78597d6117795e85e9d20e9999032e334b2e3de5004c0af8f7f82.03%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does wininit.exe normally do?

Single instance running from %SystemRoot%\System32\wininit.exe in Session 0. Launches services.exe, lsass.exe, lsm.exe.

When is wininit.exe suspicious?

More than one instance. Running from non-System32 path. Running in any session other than Session 0. Spawning unexpected child processes.

How do attackers abuse wininit.exe?

Malware masquerades as wininit.exe. Any instance outside Session 0 or System32 is malicious.

Detection guidance

Validate single instance, Session 0, System32 path. Any anomaly is high-confidence indicator.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about wininit.exe

Rocky answers questions about wininit.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.