NisSrv.exe

  • File Path: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2006.10-0\NisSrv.exe
  • Description: Microsoft Network Realtime Inspection Service

Hashes

Type Hash
MD5 8E6B6AB0394CBFEE7CA830F5D651B5B9
SHA1 323C9C2BDDB0B4D04CF9F1C126978525AA65E883
SHA256 2C46EF7000A25019BEB431DC24DCEB95EB0D7E76927F5EFDCAFF6EAF65E47E0D
SHA384 669D1E3904EB2A87391B7B7D58ACB82A97256FE2EE7DE24213EF6CAC7568482EAEB7A4AABBA4868248BF58F98966D917
SHA512 434B661B3111E7FB81AC99920785B4D274270AF1E58DDB4DA170268F32E3128721FE5FAECD6EB14CFE84005DA626104DCCFB99C65F881F7ADE4E381F039B1785
SSDEEP 49152:XbvushdfnYCxjY8C484Y2so2XRp2KNdIS0AIgIJ:TU2c8cHISBIJ

Runtime Data

Loaded Modules:

Path
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 330000024A0E8AFDF15C662D2B00000000024A
  • Thumbprint: 96384A7F5F1C438F32E2454697DC6D312A74517B
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: NisSrv.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 4.18.2006.10 (WinBuild.160101.0800)
  • Product Version: 4.18.2006.10
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of NisSrv.exe being misused. While NisSrv.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_susp_reg_disable_sec_services.yml - '\NisSrv' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.