Process

ubiquitoussigned

sihost.exe

sihost.exe is the Shell Infrastructure Host, a per-user process that runs visual and interactive parts of the Windows shell. It handles elements like the Start menu layout, taskbar transparency, the action center, context menus, and the desktop background slideshow. It works alongside Explorer and runs whenever a user is signed in.

Microsoft CorporationFirst seen 2026-06-08

File identity

File details
File type
PE32+ executable
Magic
PE32+ executable (GUI)
Original name
sihost.exe
Internal name
sihost.exe
Product
Microsoft® Windows® Operating System
Signing information
Status
Signed
Publisher
Microsoft Corporation
Signer
Microsoft Windows
Issuer
Microsoft Windows Production PCA 2011
Signature rate
100%
File version1
  • 10.0.26100.8328 (WinBuild.160101.0800)100%
File size1
  • 136.00 KB100%

Execution context

File paths1
  • C:\Windows\System32\sihost.exe100%
User context0

Not observed.

Integrity level0

Not observed.

Instances1
  • 1100%
Session1
  • Session 1100%
Token privileges1
  • SeChangeNotifyPrivilege100%

Ancestry

Parents0

Not observed.

Children0

Not observed.

Grandparents0

Not observed.

Grandchildren0

Not observed.

Behavior

Loaded modules1
Named pipes0

Not observed.

Process handles2
Command-line patterns0

Not observed.

Indicators

Hashes

Not observed.

Analysis

About this process

sihost.exe (Shell Infrastructure Host) provides shell services for the interactive desktop, the graphical plumbing the modern Windows shell needs beyond what explorer.exe itself handles. Start menu rendering, taskbar and window transparency, the action center, and the desktop background slideshow are among the features it supports. The genuine binary lives at C:\Windows\System32\sihost.exe and is signed by Microsoft.

One sihost.exe runs per interactive user session, under the logged-on user's account, and it starts as part of bringing up that user's shell. It is launched by the service infrastructure, so its parent is normally an svchost.exe. It stays running for the life of the session.

sihost.exe runs quietly in the background of every signed-in desktop. It supports the shell rather than launching applications, so it does not normally start other programs, and brief CPU spikes as the interface updates are ordinary.

Security notes

sihost.exe is rarely abused directly, so its value is as a baseline. It has a steady identity, the logged-on user's account, an svchost.exe parent, a Microsoft signature, and no child processes, which makes a deviation easy to spot. The straightforward abuse is impersonation (T1036.005): a plausible, slightly obscure name that malware borrows by running from the wrong path, under the wrong account, or without a valid signature. A sihost.exe that spawns a shell or reaches an external host is out of character.

As a persistent per-user process tied to the desktop, sihost is also a candidate for code injection (T1055), letting an attacker run in the user's context and blend into ordinary shell activity. Unusual loaded modules or network connections from an otherwise idle sihost.exe are what would point to it.

Anomaly signals7
  • Image path other than C:\Windows\System32\sihost.exehigh
  • Unsigned image or a signer other than Microsofthigh
  • Running as NT AUTHORITY\SYSTEM or a service account rather than the logged-on userhigh
  • sihost spawning child processes such as cmd.exe or powershell.exehigh
  • Parent other than svchost.exemed
  • Outbound network connections to external hostsmed
  • More instances than interactive usersmed

Telemetry

OS prevalence1
  • Microsoft Windows 11 Enterprise Evaluation100%
Observation timeline
First seen
2026-06-08
Last seen
2026-06-08
Machines
1
References

Subsearch

Hasbeen seen inof sihost.exe?