SYSINTERNALS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Sysinternals Suite provides essential Windows administration tools. Essential for system troubleshooting and security analysis.
DOWNLOAD#
# https://docs.microsoft.com/sysinternals/downloads/ # Or: \\live.sysinternals.com\tools\
PROCESS TOOLS#
PROCESS EXPLORER#
procexp.exe # GUI process viewer # Features: # - Process tree view # - DLL/handle information # - CPU/memory usage # - VirusTotal integration # - Thread analysis # Key shortcuts: Ctrl+D Show DLLs Ctrl+H Show handles Ctrl+L Show lower pane Space Refresh
PROCESS MONITOR#
procmon.exe # Real-time monitoring # Monitor: # - File system activity # - Registry activity # - Network activity # - Process/thread activity # Filters: # Process Name is powershell.exe # Operation is WriteFile # Path contains temp # Command line: procmon.exe /Quiet /BackingFile log.pml procmon.exe /LoadConfig config.pmc
PSLIST#
pslist.exe # List processes pslist.exe -t # Tree view pslist.exe -x # Extended info pslist.exe \\REMOTE # Remote system pslist.exe -u user -p pass \\REMOTE
PSKILL#
pskill.exe PID # Kill by PID pskill.exe processname # Kill by name pskill.exe \\REMOTE PID # Remote kill
PSEXEC#
psexec.exe \\TARGET cmd.exe # Remote shell psexec.exe \\TARGET -u user -p pass cmd.exe # With creds psexec.exe \\TARGET -s cmd.exe # As SYSTEM psexec.exe \\TARGET -i cmd.exe # Interactive psexec.exe \\TARGET -c program.exe # Copy and run psexec.exe @computers.txt cmd.exe # Multiple targets psexec.exe \\TARGET -d program.exe # Non-blocking
AUTORUNS#
AUTORUNS#
autoruns.exe # GUI version autorunsc.exe # Command line # Check all auto-start locations autorunsc.exe -a * # All categories autorunsc.exe -m # Hide Microsoft autorunsc.exe -v # VirusTotal check autorunsc.exe -vt # Submit unknown autorunsc.exe -c # CSV output autorunsc.exe -h # Show hashes # Categories: # Boot execute # Drivers # Codecs # Services # Scheduled tasks # DLLs # Run keys # Winlogon
NETWORK TOOLS#
TCPVIEW#
tcpview.exe # GUI network viewer tcpvcon.exe # Command line tcpvcon.exe -a # All connections tcpvcon.exe -c # CSV output tcpvcon.exe -n # No DNS resolution
PSPING#
psping.exe host:port # TCP ping psping.exe -t host:port # Continuous psping.exe -l size host:port # Bandwidth test psping.exe -b -l 8k host:port # 8KB packets
FILE TOOLS#
STRINGS#
strings.exe file.exe # ASCII strings strings.exe -b file.exe # Bytes offset strings.exe -o file.exe # Octal offset strings.exe -n 10 file.exe # Minimum length strings.exe -u file.exe # Unicode strings strings.exe -a file.exe # All strings
SIGCHECK#
sigcheck.exe file.exe # Verify signature sigcheck.exe -a file.exe # Extended info sigcheck.exe -e directory # Check directory sigcheck.exe -u -e directory # Unsigned only sigcheck.exe -v file.exe # VirusTotal check sigcheck.exe -vt file.exe # Submit unknown sigcheck.exe -h file.exe # Show hashes
STREAMS#
streams.exe file # Show ADS streams.exe -s directory # Recursive streams.exe -d file # Delete ADS
HANDLE#
handle.exe # All handles handle.exe -a # All info handle.exe -p PID # Process handles handle.exe filename # Who has file open handle.exe -c handle -p PID # Close handle
LISTDLLS#
listdlls.exe # All DLLs listdlls.exe -u # Unsigned only listdlls.exe -v # Verbose listdlls.exe PID # Specific process
SECURITY TOOLS#
ACCESSCHK#
accesschk.exe -wucs Users C:\ # Write access accesschk.exe -wuv "Everyone" * # Everyone permissions accesschk.exe -ucqv service # Service permissions accesschk.exe -uwdqs Users C:\ # Directory permissions accesschk.exe -kvuqsw HKLM\Software # Registry permissions # Useful checks: accesschk.exe -wuvc Everyone * # World-writable services accesschk.exe -wucs Users "C:\Program Files" # User writable dirs
SDELETE#
sdelete.exe -p 3 file # Secure delete (3 passes) sdelete.exe -s -q directory # Directory delete sdelete.exe -c C: # Clean free space sdelete.exe -z C: # Zero free space
LOGONSESSIONS#
logonsessions.exe # Active sessions logonsessions.exe -p # With processes
PSGETSID#
psgetsid.exe # Local SID psgetsid.exe user # User SID psgetsid.exe \\COMPUTER # Remote SID psgetsid.exe S-1-5-... # SID to name
SYSTEM TOOLS#
PSINFO#
psinfo.exe # System info psinfo.exe \\REMOTE # Remote system psinfo.exe -h # Hotfix info psinfo.exe -s # Software info psinfo.exe -d # Disk info
PSSERVICE#
psservice.exe query # List services psservice.exe query servicename # Service info psservice.exe start servicename # Start service psservice.exe stop servicename # Stop service psservice.exe config servicename # Service config psservice.exe \\REMOTE query # Remote services
PSLOGGEDON#
psloggedon.exe # Local logins psloggedon.exe \\REMOTE # Remote logins psloggedon.exe -l # Local only
DISK TOOLS#
DISKEXT#
diskext.exe # Disk extents DU -- du.exe directory # Disk usage du.exe -l 2 directory # Depth limit
JUNCTION#
junction.exe link target # Create junction junction.exe -d link # Delete junction junction.exe -s directory # List junctions
DEBUGGING#
PROCDUMP#
procdump.exe -ma PID # Full dump procdump.exe -mm PID # Mini dump procdump.exe -e 1 -f "" PID # Dump on exception procdump.exe -h PID # Dump on hang procdump.exe -c 90 PID # Dump at 90% CPU procdump.exe -m 500 PID # Dump at 500MB memory procdump.exe -ma -i C:\dumps # Install as AEDebug
DEBUGVIEW#
dbgview.exe # Debug output viewer dbgview.exe /l logfile.txt # Log to file
LIVEKD#
livekd.exe # Live kernel debug livekd.exe -w # WinDbg GUI
QUICK REFERENCE#
# Process analysis procexp.exe # Process Explorer procmon.exe # Process Monitor autoruns.exe # Auto-starts # Remote execution psexec.exe \\TARGET cmd.exe # Remote shell pslist.exe \\TARGET # Remote processes pskill.exe \\TARGET PID # Remote kill # File analysis strings.exe file.exe # Extract strings sigcheck.exe -v file.exe # VirusTotal check listdlls.exe -u # Unsigned DLLs # Security accesschk.exe -wuvc Everyone * # Permission check handle.exe filename # Who has file open