code.exe
πͺVSCode binary, also portable (CLI) version
GfxDownloadWrapper.exe
πͺRemote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path.
Powershell.exe
πͺPowershell.exe is a a task-based command-line shell built on .NET.
AddinUtil.exe
πͺ.NET Tool used for updating cache files for Microsoft Office Add-Ins.
AppInstaller.exe
πͺTool used for installation of AppX/MSIX applications on Windows 10
Aspnet_Compiler.exe
πͺASP.NET Compilation Tool
At.exe
πͺSchedule periodic tasks
Atbroker.exe
πͺHelper binary for Assistive Technology (AT)
Bash.exe
πͺFile used by Windows subsystem for Linux
Bitsadmin.exe
πͺUsed for managing background intelligent transfer
CertOC.exe
πͺUsed for installing certificates
CertReq.exe
πͺUsed for requesting and managing certificates
Certutil.exe
πͺWindows binary used for handling certificates
Change.exe
πͺRemote Desktop Services MultiUser Change Utility
Cipher.exe
πͺFile Encryption Utility
Cmd.exe
πͺThe command-line interpreter in Windows
Cmdkey.exe
πͺcreates, lists, and deletes stored user names and passwords or credentials.
cmdl32.exe
πͺMicrosoft Connection Manager Auto-Download
Cmstp.exe
πͺInstalls or removes a Connection Manager service profile.
Colorcpl.exe
πͺBinary that handles color management
ComputerDefaults.exe
πͺComputerDefaults.exe is a Windows system utility for managing default applications for tasks like web browsing, emailing, and media playback.
ConfigSecurityPolicy.exe
πͺBinary part of Windows Defender. Used to manage settings in Windows Defender. You can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
Conhost.exe
πͺConsole Window host
Control.exe
πͺBinary used to launch controlpanel items in Windows
Csc.exe
πͺBinary file used by .NET Framework to compile C# code
Cscript.exe
πͺBinary used to execute scripts in Windows
CustomShellHost.exe
πͺA host process that is used by custom shells when using Windows in Kiosk mode.
DataSvcUtil.exe
πͺDataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
Desktopimgdownldr.exe
πͺWindows binary used to configure lockscreen/desktop image
DeviceCredentialDeployment.exe
πͺDevice Credential Deployment
Dfsvc.exe
πͺClickOnce engine in Windows used by .NET
Diantz.exe
πͺBinary that package existing files into a cabinet (.cab) file
Diskshadow.exe
πͺDiskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
Dnscmd.exe
πͺA command-line interface for managing DNS servers
Esentutl.exe
πͺBinary for working with Microsoft Joint Engine Technology (JET) database
Eudcedit.exe
πͺPrivate Character Editor Windows Utility
Eventvwr.exe
πͺDisplays Windows Event Logs in a GUI window.
Expand.exe
πͺBinary that expands one or more compressed files
Explorer.exe
πͺBinary used for managing files and system components within Windows
Extexport.exe
πͺLoad a DLL located in the c:\test folder with a specific name.
Extrac32.exe
πͺExtract to ADS, copy or overwrite a file with Extrac32.exe
Findstr.exe
πͺWrite to ADS, discover, or download files with Findstr.exe
Finger.exe
πͺDisplays information about a user or users on a specified remote computer that is running the Finger service or daemon
fltMC.exe
πͺFilter Manager Control Program used by Windows
Forfiles.exe
πͺSelects and executes a command on a file or set of files. This command is useful for batch processing.
Fsutil.exe
πͺFile System Utility
Ftp.exe
πͺA binary designed for connecting to FTP servers
Gpscript.exe
πͺUsed by group policy to process scripts
Hh.exe
πͺBinary used for processing chm files in Windows
IMEWDBLD.exe
πͺMicrosoft IME Open Extended Dictionary Module
Ie4uinit.exe
πͺExecutes commands from a specially prepared ie4uinit.inf file.
iediagcmd.exe
πͺDiagnostics Utility for Internet Explorer
Ieexec.exe
πͺThe IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
Ilasm.exe
πͺused for compile c# code into dll or exe.
Infdefaultinstall.exe
πͺBinary used to perform installation based on content inside inf files
Installutil.exe
πͺThe Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
iscsicpl.exe
πͺMicrosoft iSCSI Initiator Control Panel tool
Jsc.exe
πͺBinary file used by .NET to compile JavaScript code to .exe or .dll format
Ldifde.exe
πͺCreates, modifies, and deletes LDAP directory objects.
Makecab.exe
πͺBinary to package existing files into a cabinet (.cab) file
Mavinject.exe
πͺUsed by App-v in Windows
Microsoft.Workflow.Compiler.exe
πͺA utility included with .NET that is capable of compiling and executing C# or VB.net code.
Mmc.exe
πͺLoad snap-ins to locally and remotely manage Windows systems
MpCmdRun.exe
πͺBinary part of Windows Defender. Used to manage settings in Windows Defender
Msbuild.exe
πͺUsed to compile and execute code
Msconfig.exe
πͺMSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows
Msdt.exe
πͺMicrosoft diagnostics tool
Msedge.exe
πͺMicrosoft Edge browser
Mshta.exe
πͺUsed by Windows to execute html applications. (.hta)
Msiexec.exe
πͺUsed by Windows to execute msi files
Netsh.exe
πͺNetsh is a Windows tool used to manipulate network interface settings.
Ngen.exe
πͺMicrosoft Native Image Generator.
Odbcconf.exe
πͺUsed in Windows for managing ODBC connections
OfflineScannerShell.exe
πͺWindows Defender Offline Shell
OneDriveStandaloneUpdater.exe
πͺOneDrive Standalone Updater
Pcalua.exe
πͺProgram Compatibility Assistant
Pcwrun.exe
πͺProgram Compatibility Wizard
Pktmon.exe
πͺCapture Network Packets on the windows 10 with October 2018 Update or later.
Pnputil.exe
πͺUsed for installing drivers
Presentationhost.exe
πͺFile is used for executing Browser applications
Print.exe
πͺUsed by Windows to send files to the printer
PrintBrm.exe
πͺPrinter Migration Command-Line Tool
Provlaunch.exe
πͺLauncher process
Psr.exe
πͺWindows Problem Steps Recorder, used to record screen and clicks.
Query.exe
πͺRemote Desktop Services MultiUser Query Utility
Rasautou.exe
πͺWindows Remote Access Dialer
rdrleakdiag.exe
πͺMicrosoft Windows resource leak diagnostic tool
Reg.exe
πͺUsed to manipulate the registry
Regasm.exe
πͺPart of .NET
Regedit.exe
πͺUsed by Windows to manipulate registry
Regini.exe
πͺUsed to manipulate the registry
Register-cimprovider.exe
πͺUsed to register new wmi providers
Regsvcs.exe
πͺRegsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
Regsvr32.exe
πͺUsed by Windows to register dlls
Replace.exe
πͺUsed to replace file with another file
Reset.exe
πͺRemote Desktop Services Reset Utility
Rpcping.exe
πͺUsed to verify rpc connection
Rundll32.exe
πͺUsed by Windows to execute dll files
Runexehelper.exe
πͺLauncher process
Runonce.exe
πͺExecutes a Run Once Task that has been configured in the registry
Runscripthelper.exe
πͺExecute target PowerShell script
Sc.exe
πͺUsed by Windows to manage services
Schtasks.exe
πͺSchedule periodic tasks
Scriptrunner.exe
πͺExecute binary through proxy binary to evade defensive counter measures
Setres.exe
πͺConfigures display settings
SettingSyncHost.exe
πͺHost Process for Setting Synchronization
Sftp.exe
πͺsftp.exe is a Windows command-line utility that uses the Secure File Transfer Protocol (SFTP) to securely transfer files between a local machine and a remote server.
ssh.exe
πͺSsh.exe is the OpenSSH compatible client can be used to connect to Windows 10 (build 1809 and later) and Windows Server 2019 devices.
Stordiag.exe
πͺStorage diagnostic tool
SyncAppvPublishingServer.exe
πͺUsed by App-v to get App-v server lists
Tar.exe
πͺUsed by Windows to extract and create archives.
Ttdinject.exe
πͺUsed by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
Tttracer.exe
πͺUsed by Windows 1809 and newer to Debug Time Travel
Unregmp2.exe
πͺMicrosoft Windows Media Player Setup Utility
vbc.exe
πͺBinary file used for compile vbs code
Verclsid.exe
πͺUsed to verify a COM object before it is instantiated by Windows Explorer
Wab.exe
πͺWindows address book manager
wbadmin.exe
πͺWindows Backup Administration utility
wbemtest.exe
πͺWMI/WBEM Test Binary
winget.exe
πͺWindows Package Manager tool
Wlrmdr.exe
πͺWindows Logon Reminder executable
Wmic.exe
πͺThe WMI command-line (WMIC) utility provides a command-line interface for WMI
WorkFolders.exe
πͺWork Folders
Wscript.exe
πͺUsed by Windows to execute scripts
Wsreset.exe
πͺUsed to reset Windows Store settings according to its manifest file
wuauclt.exe
πͺWindows Update Client
Xwizard.exe
πͺExecute custom class that has been added to the registry or download a file with Xwizard.exe
msedge_proxy.exe
πͺMicrosoft Edge Browser
msedgewebview2.exe
πͺmsedgewebview2.exe is the executable file for Microsoft Edge WebView2, which is a web browser control used by applications to display web content.
wt.exe
πͺWindows Terminal
Advpack.dll
πͺUtility for installing software and drivers with rundll32.exe
Desk.cpl
πͺDesktop Settings Control Panel
Dfshim.dll
πͺClickOnce engine in Windows used by .NET
Ieadvpack.dll
πͺINF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
Ieframe.dll
πͺInternet Browser DLL for translating HTML code.
Mshtml.dll
πͺMicrosoft HTML Viewer
Pcwutl.dll
πͺMicrosoft HTML Viewer
PhotoViewer.dll
πͺWindows Photo Viewer
Scrobj.dll
πͺWindows Script Component Runtime
Setupapi.dll
πͺWindows Setup Application Programming Interface
Shdocvw.dll
πͺShell Doc Object and Control Library.
Shell32.dll
πͺWindows Shell Common Dll
Shimgvw.dll
πͺPhoto Gallery Viewer
Syssetup.dll
πͺWindows NT System Setup
Url.dll
πͺInternet Shortcut Shell Extension DLL.
Zipfldr.dll
πͺCompressed Folder library
Comsvcs.dll
πͺCOM+ Services
CL_LoadAssembly.ps1
πͺPowerShell Diagnostic Script
CL_Mutexverifiers.ps1
πͺProxy execution with CL_Mutexverifiers.ps1
CL_Invocation.ps1
πͺAero diagnostics script
Launch-VsDevShell.ps1
πͺLocates and imports a Developer PowerShell module and calls the Enter-VsDevShell cmdlet
Manage-bde.wsf
πͺScript for managing BitLocker
Pubprn.vbs
πͺProxy execution with Pubprn.vbs
Syncappvpublishingserver.vbs
πͺScript used related to app-v and publishing server
UtilityFunctions.ps1
πͺPowerShell Diagnostic Script
winrm.vbs
πͺScript used for manage Windows RM settings
Pester.bat
πͺUsed as part of the Powershell pester
AccCheckConsole.exe
πͺVerifies UI accessibility requirements
adplus.exe
πͺDebugging tool included with Windows Debugging Tools
AgentExecutor.exe
πͺIntune Management Extension included on Intune Managed Devices
AppLauncher.exe
πͺUser Experience Virtualization tool that launches applications under monitoring to capture and synchronize user settings.
AppCert.exe
πͺWindows App Certification Kit command-line tool.
Appvlp.exe
πͺApplication Virtualization Utility Included with Microsoft Office 2016
Bcp.exe
πͺMicrosoft SQL Server Bulk Copy Program utility for importing and exporting data between SQL Server instances and data files.
Bginfo.exe
πͺBackground Information Utility included with SysInternals Suite
Cdb.exe
πͺDebugging tool included with Windows Debugging Tools.
coregen.exe
πͺBinary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
Createdump.exe
πͺMicrosoft .NET Runtime Crash Dump Generator (included in .NET Core)
csi.exe
πͺCommand line interface included with Visual Studio.
DefaultPack.EXE
πͺThis binary can be downloaded along side multiple software downloads on the Microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
Devinit.exe
πͺVisual Studio 2019 tool
Devtoolslauncher.exe
πͺBinary will execute specified binary. Part of VS/VScode installation.
dnx.exe
πͺ.NET Execution environment file included with .NET.
Dotnet.exe
πͺdotnet.exe comes with .NET Framework
dsdbutil.exe
πͺDsdbutil is a command-line tool that is built into Windows Server. It is available if you have the AD LDS server role installed. Can be used as a command line utility to export Active Directory.
dtutil.exe
πͺMicrosoft command line utility used to manage SQL Server Integration Services packages.
Dump64.exe
πͺMemory dump tool that comes with Microsoft Visual Studio
DumpMinitool.exe
πͺDump tool part Visual Studio 2022
Dxcap.exe
πͺDirectX diagnostics/debugger included with Visual Studio.
ECMangen.exe
πͺCommand-line tool for managing certificates in Microsoft Exchange Server.
Excel.exe
πͺMicrosoft Office binary
Fsi.exe
πͺ64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK.
FsiAnyCpu.exe
πͺ32/64-bit FSharp (F#) Interpreter included with Visual Studio.
IntelliTrace.exe
πͺVisual Studio command-line tool for collecting and managing diagnostic trace files.
Mftrace.exe
πͺTrace log generation tool for Media Foundation Tools.
Microsoft.NodejsTools.PressAnyKey.exe
πͺPart of the NodeJS Visual Studio tools.
Mpiexec.exe
πͺCommand-line tool for running Message Passing Interface (MPI) applications.
MSAccess.exe
πͺMicrosoft Office component
Msdeploy.exe
πͺMicrosoft tool used to deploy Web Applications.
MsoHtmEd.exe
πͺMicrosoft Office component
Mspub.exe
πͺMicrosoft Publisher
msxsl.exe
πͺCommand line utility used to perform XSL transformations.
ntdsutil.exe
πͺCommand line utility used to export Active Directory.
Ntsd.exe
πͺSymbolic Debugger for Windows.
OpenConsole.exe
πͺConsole Window host for Windows Terminal
Pixtool.exe
πͺCommand line utility for taking and analyzing PIX GPU captures.
Powerpnt.exe
πͺMicrosoft Office binary.
Procdump.exe
πͺSysInternals Memory Dump Tool
ProtocolHandler.exe
πͺMicrosoft Office binary
rcsi.exe
πͺNon-Interactive command line inerface included with Visual Studio.
Remote.exe
πͺDebugging tool included with Windows Debugging Tools
Sqldumper.exe
πͺDebugging utility included with Microsoft SQL.
Sqlps.exe
πͺTool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
SQLToolsPS.exe
πͺTool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
Squirrel.exe
πͺBinary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.
te.exe
πͺTesting tool included with Microsoft Test Authoring and Execution Framework (TAEF).
Teams.exe
πͺElectron runtime binary which runs the Teams application
TestWindowRemoteAgent.exe
πͺTestWindowRemoteAgent.exe is the command-line tool to establish RPC
Tracker.exe
πͺTool included with Microsoft .Net Framework.
Update.exe
πͺBinary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.
VSDiagnostics.exe
πͺCommand-line tool used for performing diagnostics.
VSIISExeLauncher.exe
πͺBinary will execute specified binary. Part of VS/VScode installation.
Visio.exe
πͺMicrosoft Visio Executable
VisualUiaVerifyNative.exe
πͺA Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
VSLaunchBrowser.exe
πͺMicrosoft Visual Studio browser launcher tool for web applications debugging
Vshadow.exe
πͺVShadow is a command-line tool that can be used to create and manage volume shadow copies.
vsjitdebugger.exe
πͺJust-In-Time (JIT) debugger included with Visual Studio
WFMFormat.exe
πͺCommand-line tool used for pretty-print a dump file generated by Message Farm Analyzer tool.
Wfc.exe
πͺThe Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK).
WinDbg.exe
πͺWindows Debugger for advanced user-mode and kernel-mode debugging.
WinProj.exe
πͺMicrosoft Project Executable
Winword.exe
πͺMicrosoft Office binary
Wsl.exe
πͺWindows subsystem for Linux executable
XBootMgr.exe
πͺWindows Performance Toolkit binary used to start performance traces.
XBootMgrSleep.exe
πͺWindows Performance Toolkit binary used for tracing and analyzing system performance during sleep and resume transitions.
devtunnel.exe
πͺBinary to enable forwarded ports on windows operating systems.
vsls-agent.exe
πͺAgent for Visual Studio Live Share (Code Collaboration)
vstest.console.exe
πͺVSTest.Console.exe is the command-line tool to run tests
winfile.exe
πͺWindows File Manager executable
xsd.exe
πͺXML Schema Definition Tool included with the Windows Software Development Kit (SDK).