← All cheat sheets

SYSINTERNALS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Sysinternals Suite provides essential Windows administration tools.
Essential for system troubleshooting and security analysis.

DOWNLOAD#

# https://docs.microsoft.com/sysinternals/downloads/
# Or: \\live.sysinternals.com\tools\

PROCESS TOOLS#


    

PROCESS EXPLORER#

procexp.exe                          # GUI process viewer

# Features:
# - Process tree view
# - DLL/handle information
# - CPU/memory usage
# - VirusTotal integration
# - Thread analysis

# Key shortcuts:
Ctrl+D      Show DLLs
Ctrl+H      Show handles
Ctrl+L      Show lower pane
Space       Refresh

PROCESS MONITOR#

procmon.exe                          # Real-time monitoring

# Monitor:
# - File system activity
# - Registry activity
# - Network activity
# - Process/thread activity

# Filters:
# Process Name is powershell.exe
# Operation is WriteFile
# Path contains temp

# Command line:
procmon.exe /Quiet /BackingFile log.pml
procmon.exe /LoadConfig config.pmc

PSLIST#

pslist.exe                           # List processes
pslist.exe -t                        # Tree view
pslist.exe -x                        # Extended info
pslist.exe \\REMOTE                  # Remote system
pslist.exe -u user -p pass \\REMOTE

PSKILL#

pskill.exe PID                       # Kill by PID
pskill.exe processname               # Kill by name
pskill.exe \\REMOTE PID             # Remote kill

PSEXEC#

psexec.exe \\TARGET cmd.exe                     # Remote shell
psexec.exe \\TARGET -u user -p pass cmd.exe     # With creds
psexec.exe \\TARGET -s cmd.exe                  # As SYSTEM
psexec.exe \\TARGET -i cmd.exe                  # Interactive
psexec.exe \\TARGET -c program.exe              # Copy and run
psexec.exe @computers.txt cmd.exe               # Multiple targets
psexec.exe \\TARGET -d program.exe              # Non-blocking

AUTORUNS#


    

AUTORUNS#

autoruns.exe                         # GUI version
autorunsc.exe                        # Command line

# Check all auto-start locations
autorunsc.exe -a *                   # All categories
autorunsc.exe -m                     # Hide Microsoft
autorunsc.exe -v                     # VirusTotal check
autorunsc.exe -vt                    # Submit unknown
autorunsc.exe -c                     # CSV output
autorunsc.exe -h                     # Show hashes

# Categories:
# Boot execute
# Drivers
# Codecs
# Services
# Scheduled tasks
# DLLs
# Run keys
# Winlogon

NETWORK TOOLS#


    

TCPVIEW#

tcpview.exe                          # GUI network viewer
tcpvcon.exe                          # Command line

tcpvcon.exe -a                       # All connections
tcpvcon.exe -c                       # CSV output
tcpvcon.exe -n                       # No DNS resolution

PSPING#

psping.exe host:port                 # TCP ping
psping.exe -t host:port              # Continuous
psping.exe -l size host:port         # Bandwidth test
psping.exe -b -l 8k host:port        # 8KB packets

FILE TOOLS#


    

STRINGS#

strings.exe file.exe                 # ASCII strings
strings.exe -b file.exe              # Bytes offset
strings.exe -o file.exe              # Octal offset
strings.exe -n 10 file.exe           # Minimum length
strings.exe -u file.exe              # Unicode strings
strings.exe -a file.exe              # All strings

SIGCHECK#

sigcheck.exe file.exe                # Verify signature
sigcheck.exe -a file.exe             # Extended info
sigcheck.exe -e directory            # Check directory
sigcheck.exe -u -e directory         # Unsigned only
sigcheck.exe -v file.exe             # VirusTotal check
sigcheck.exe -vt file.exe            # Submit unknown
sigcheck.exe -h file.exe             # Show hashes

STREAMS#

streams.exe file                     # Show ADS
streams.exe -s directory             # Recursive
streams.exe -d file                  # Delete ADS

HANDLE#

handle.exe                           # All handles
handle.exe -a                        # All info
handle.exe -p PID                    # Process handles
handle.exe filename                  # Who has file open
handle.exe -c handle -p PID          # Close handle

LISTDLLS#

listdlls.exe                         # All DLLs
listdlls.exe -u                      # Unsigned only
listdlls.exe -v                      # Verbose
listdlls.exe PID                     # Specific process

SECURITY TOOLS#


    

ACCESSCHK#

accesschk.exe -wucs Users C:\        # Write access
accesschk.exe -wuv "Everyone" *      # Everyone permissions
accesschk.exe -ucqv service          # Service permissions
accesschk.exe -uwdqs Users C:\       # Directory permissions
accesschk.exe -kvuqsw HKLM\Software  # Registry permissions

# Useful checks:
accesschk.exe -wuvc Everyone *       # World-writable services
accesschk.exe -wucs Users "C:\Program Files"  # User writable dirs

SDELETE#

sdelete.exe -p 3 file                # Secure delete (3 passes)
sdelete.exe -s -q directory          # Directory delete
sdelete.exe -c C:                    # Clean free space
sdelete.exe -z C:                    # Zero free space

LOGONSESSIONS#

logonsessions.exe                    # Active sessions
logonsessions.exe -p                 # With processes

PSGETSID#

psgetsid.exe                         # Local SID
psgetsid.exe user                    # User SID
psgetsid.exe \\COMPUTER              # Remote SID
psgetsid.exe S-1-5-...               # SID to name

SYSTEM TOOLS#


    

PSINFO#

psinfo.exe                           # System info
psinfo.exe \\REMOTE                  # Remote system
psinfo.exe -h                        # Hotfix info
psinfo.exe -s                        # Software info
psinfo.exe -d                        # Disk info

PSSERVICE#

psservice.exe query                  # List services
psservice.exe query servicename      # Service info
psservice.exe start servicename      # Start service
psservice.exe stop servicename       # Stop service
psservice.exe config servicename     # Service config
psservice.exe \\REMOTE query         # Remote services

PSLOGGEDON#

psloggedon.exe                       # Local logins
psloggedon.exe \\REMOTE              # Remote logins
psloggedon.exe -l                    # Local only

DISK TOOLS#


    

DISKEXT#

diskext.exe                          # Disk extents

DU
--
du.exe directory                     # Disk usage
du.exe -l 2 directory                # Depth limit

JUNCTION#

junction.exe link target             # Create junction
junction.exe -d link                 # Delete junction
junction.exe -s directory            # List junctions

DEBUGGING#


    

PROCDUMP#

procdump.exe -ma PID                 # Full dump
procdump.exe -mm PID                 # Mini dump
procdump.exe -e 1 -f "" PID          # Dump on exception
procdump.exe -h PID                  # Dump on hang
procdump.exe -c 90 PID               # Dump at 90% CPU
procdump.exe -m 500 PID              # Dump at 500MB memory
procdump.exe -ma -i C:\dumps         # Install as AEDebug

DEBUGVIEW#

dbgview.exe                          # Debug output viewer
dbgview.exe /l logfile.txt           # Log to file

LIVEKD#

livekd.exe                           # Live kernel debug
livekd.exe -w                        # WinDbg GUI

QUICK REFERENCE#

# Process analysis
procexp.exe                          # Process Explorer
procmon.exe                          # Process Monitor
autoruns.exe                         # Auto-starts

# Remote execution
psexec.exe \\TARGET cmd.exe          # Remote shell
pslist.exe \\TARGET                  # Remote processes
pskill.exe \\TARGET PID              # Remote kill

# File analysis
strings.exe file.exe                 # Extract strings
sigcheck.exe -v file.exe             # VirusTotal check
listdlls.exe -u                      # Unsigned DLLs

# Security
accesschk.exe -wuvc Everyone *       # Permission check
handle.exe filename                  # Who has file open