Autoruns
Sysinternals tool that shows every program configured to run at startup, logon or boot on Windows.
Open the official app on learn.microsoft.com
This tool is hosted by its maintainers. Click below to open learn.microsoft.com in a new tab — it's their official demo.
Browse security tools →What's next with Autoruns?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Autoruns?
Autoruns is a comprehensive startup monitor developed by Microsoft's Sysinternals team. It provides detailed visibility into programs configured to execute automatically during system boot, user login, or when launching Windows applications like Internet Explorer and media players. The tool scans multiple auto-start locations, including startup folders, Registry keys, and system services, to identify potential security risks or performance bottlenecks. Security professionals, system administrators, and advanced users leverage Autoruns to audit system configurations, detect unauthorized software, and troubleshoot startup-related issues. Its primary purpose is to address the challenge of managing and securing the complex web of auto-start entries that can compromise system integrity or degrade performance.
How it works
Autoruns is a diagnostic utility that maps all auto-start configurations across Windows systems, offering granular control over startup processes. It prioritizes transparency by revealing both legitimate and potentially malicious entries, such as drivers, services, and registry-based triggers. The tool's purpose extends beyond basic startup management; it serves as a critical security tool for identifying stealthy malware or rogue software that may evade standard detection methods by leveraging hidden auto-start mechanisms. Autoruns scans over 50 auto-start locations, including Run, RunOnce, Task Scheduler, and Winlogon notifications, while supporting advanced analysis of shell extensions and browser helper objects. Its 'Hide Signed Microsoft Entries' feature filters out trusted Microsoft components, enabling users to focus on third-party applications. The tool also provides detailed insights into service configurations and user-specific auto-start settings across multiple accounts.
How to use it
- 1Download and launch Autoruns from the Sysinternals website. 2. Navigate through the tree-view interface to explore different auto-start categories, such as 'Startup' or 'Services'. 3. Toggle the 'Hide Signed Microsoft Entries' option to filter non-Microsoft entries. 4. Right-click suspicious entries to disable or delete them. Practical tips include comparing system configurations across accounts and verifying digital signatures for unknown entries.
What it can do
- startup monitor
Use cases
Assumptions and limitations
Assumptions
- source: https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- license: Proprietary — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- Does not cover all edge cases for newer Windows versions or third-party boot loaders
- Requires administrative privileges to modify certain auto-start configurations
- Lacks real-time monitoring of dynamic startup changes
- May generate false positives when analyzing complex system configurations
Understanding the result
Sysinternals tool that shows every program configured to run at startup, logon or boot on Windows.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- Proprietary License
Upstream project
Frequently asked
What types of auto-start locations does Autoruns scan?
Autoruns examines over 50 locations including startup folders, Registry keys (HKLM\Software\Microsoft\Windows\CurrentVersion\Run, HKCU\Run), Task Scheduler, Winlogon notifications, and service configurations. It also analyzes browser helper objects, shell extensions, and user-specific settings across multiple accounts.
How does Autoruns distinguish between legitimate and malicious entries?
The tool uses heuristics and digital signature verification to flag suspicious entries. Its 'Hide Signed Microsoft Entries' feature filters out trusted Microsoft components, while users must manually verify unknown entries. Autoruns does not automatically label entries as malicious but provides context for risk assessment.
How do I disable a suspicious auto-start entry?
Right-click the entry in Autoruns and select 'Disable' or 'Delete'. For registry-based entries, the tool provides direct access to edit the relevant Registry key. Always back up system settings before making changes, and verify the entry's legitimacy through digital signature checks or behavioral analysis.
How does Autoruns compare to alternatives like msconfig or Task Manager?
Unlike msconfig and Task Manager, Autoruns provides exhaustive coverage of auto-start locations, including hidden and less commonly accessed configurations. It also offers advanced analysis of system services and user-specific settings, making it more suitable for in-depth security audits compared to basic task management tools.
What should I do if Autoruns shows missing or corrupted entries?
Verify the entry's legitimacy by checking its digital signature and reviewing its behavior. For missing entries, ensure the associated file exists in the specified location. Corrupted entries may require system file checks (sfc /scannow) or reinstallation of the affected software. Always exercise caution when modifying critical system entries.