esentutl

MITRE ATT&CK: S0404 View on attack.mitre.org

Aliases: esentutl.exe, esentutl

Operating systems
windows
Profile updated
2026-07-07 15:32:32

Context

esentutl is a command-line tool that provides database utilities for the Windows Extensible Storage Engine.

Detection coverage

  • 132 Sigma rules

Malware & tools used

  • Direct Volume Access (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • NTDS (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Data from Local System (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0404 (report)
  • Microsoft — Hh875546(V=Ws.11) (report)

External references