RuntimeBroker.exe acts as a proxy between the constrained
Universal Windows Platform (UWP) apps (formerly called Metro apps) and the
full Windows API. UWP apps have limited capability to interface with hardware
and the file system. Broker processes such as RuntimeBroker.exe
are therefore used to provide the necessary level of access for UWP
apps. Generally, there will be one RuntimeBroker.exe
for each UWP
app. For example, starting Calculator.exe
will cause a corresponding
RuntimeBroker.exe
process to initiate.
Executable’s image path.
%SystemRoot%\System32\RuntimeBroker.exe
A process which spawned the analyzed process.
svchost.exe
Expected number of processes running which may normally run on Windows.
One or more
Windows account with which the process was launched. This defines what privileges given process has.
Typically the logged-on user(s)
Expected time of process to be launched.
Start times vary greatly