Process

unknown

quser.exe

quser.exe shows the user sessions on a machine: who is logged on, whether each session is active or disconnected, and how long it has been idle. Administrators use it to see who is using a server. Attackers use it to learn who else is on a host before acting, to avoid notice and to hunt for privileged sessions worth stealing.

File identity

File details

Not observed.

Signing information

Not observed.

File version0

Not observed.

File size0

Not observed.

Execution context

File paths0

Not observed.

User context0

Not observed.

Integrity level0

Not observed.

Instances0

Not observed.

Session0

Not observed.

Token privileges0

Not observed.

Ancestry

Parents0

Not observed.

Children0

Not observed.

Grandparents0

Not observed.

Grandchildren0

Not observed.

Behavior

Loaded modules0

Not observed.

Named pipes0

Not observed.

Process handles0

Not observed.

Command-line patterns0

Not observed.

Indicators

Hashes

Not observed.

Analysis

About this process

quser.exe, also available as query user, lists interactive and Remote Desktop sessions on the local machine or, with /server:<host>, a remote one. For each session it shows the user name, the session name and ID, the state, the idle time, and the logon time. The genuine binary lives at C:\Windows\System32\quser.exe.

Legitimately, quser is run by administrators to check who is connected before maintenance or to free up sessions. It only reads session state.

Security notes

quser answers a question an intruder cares about: who else is here (T1033). Knowing which users are logged on, and which sessions are active rather than idle, helps an attacker time their actions to avoid a watching administrator and, more usefully, spot privileged accounts with live sessions whose tokens or credentials are worth stealing.

A single quser is ordinary administration. quser run by an unusual parent, against remote hosts, or alongside other discovery commands is the reconnaissance pattern to flag.

Anomaly signals4
  • Image path other than C:\Windows\System32\quser.exehigh
  • Parent is an Office application, a script host, or an unfamiliar processhigh
  • Run shortly after access to enumerate other sessionsmed
  • A remote target, /server:<host>med

Telemetry

OS prevalence0

Not observed.

Observation timeline

Not observed.

References

Subsearch

Hasbeen seen inof quser.exe?