RuntimeBroker.exe acts as a proxy between the constrained
Universal Windows Platform (UWP) apps (formerly called Metro apps) and the
full Windows API. UWP apps have limited capability to interface with hardware
and the file system. Broker processes such as RuntimeBroker.exe
are therefore used to provide the necessary level of access for UWP
apps. Generally, there will be one RuntimeBroker.exe for each UWP
app. For example, starting Calculator.exe will cause a corresponding
RuntimeBroker.exe process to initiate.
Executable’s image path.
%SystemRoot%\System32\RuntimeBroker.exeA process which spawned the analyzed process.
svchost.exeExpected number of processes running which may normally run on Windows.
One or moreWindows account with which the process was launched. This defines what privileges given process has.
Typically the logged-on user(s)Expected time of process to be launched.
Start times vary greatly