MsSense.exe

  • File Path: C:\program files\Windows Defender Advanced Threat Protection\MsSense.exe
  • Description: Windows Defender Advanced Threat Protection Service Executable

Hashes

Type Hash
MD5 5E08AEF078E44853F8789DB49E831964
SHA1 B6288E37D275389919F6AEBD07E59771E1A5E084
SHA256 CCF0F9A4C6E37F6DA991FDAF1CCCC978770F9417A4509ACFE878F46CC3A9BE4C
SHA384 1B4646FA7A34CB1E9CBF04C88A29E460DD7B7D74A498FA16A2BF0C2A43C0C20724696E37D0F52F16EBDDA9B97A7C1D13
SHA512 76A42E6E9D177C032D94188A9246356DF4065F153E37C75DF1AEE55E00D58BEBBCA8A9E74EAEE7A1D8DC91F506454B685CC56B119001C91919C510AEE8FE38D3
SSDEEP 49152:D21T+dqFiTJP3qZRq57U5WGx7DAf2Ry0po3ljoskLHEhW0SumkvmpSNF5A6GN9yG:ywwE57U5NtDipRljlA6E9OZrsTcxQ

Runtime Data

Loaded Modules:

Path
C:\program files\Windows Defender Advanced Threat Protection\MsSense.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: MsSense.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.7430.19041.423 (WinBuild.160101.0800)
  • Product Version: 10.7430.19041.423
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of MsSense.exe being misused. While MsSense.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
stockpile 1258b063-27d6-489b-a677-4807faacf868.yml "mssense", Apache-2.0

MIT License. Copyright (c) 2020-2021 Strontic.