December 12th, 2008 by ahoog

Sysinternals

Sysinternals is a suite of utilities to help you manage, troubleshoot and diagnose Windows systems and applications.  Windows and DOS lacked many of the management utilities that other operating systems, particularly Unix, had.  The Sysinternals team began to develop these tools and in 1996 they were bought by Microsoft.

The utilities remain free (arguably they should simply be a standard part of a Windows installation) and are actively developed.  They are particularly useful when performing live analysis of a machine (often done when a computer has been hacked and you want to understand the root exploit and ensuing nastiness).  There is also an interesting option of running the utilities directly from their website.  Their Troubleshooting Utilities bundle including the following tools:

  • AccessChk
  • AccessEnum
  • AdExplorer
  • AdRestore
  • Autologon
  • Autoruns
  • BgInfo
  • CacheSet
  • ClockRes
  • Contig
  • Coreinfo
  • Ctrl2Cap
  • DebugView
  • Desktops
  • Disk Usage (DU)
  • DiskExt
  • DiskMon
  • DiskView
  • EFSDump
  • FileMon
  • Handle
  • Hex2dec
  • Junction
  • LDMDump
  • ListDLLs
  • LiveKd
  • LoadOrder
  • LogonSessions
  • NewSid
  • NTFSInfo
  • PageDefrag
  • PendMoves
  • PortMon
  • Process Monitor
  • ProcessExplorer
  • ProcFeatures
  • PsExec
  • PsFile
  • PsGetSid
  • PsInfo
  • PsKill
  • PsList
  • PsLoggedOn
  • PsLogList
  • PsPasswd
  • PsService
  • PsShutdown
  • PsSuspend
  • RegDelNull
  • RegJump
  • RegMon
  • RootkitRevealer
  • SDelete
  • ShareEnum
  • ShellRunas
  • SigCheck
  • Streams
  • Strings
  • Sync
  • TCPView
  • VolumeID
  • WhoIs
  • WinObj
  • ZoomIt

They are very easy to install and use…I would encourage anyone interested to test it out anytime on their Windows computer.

  • Share/Bookmark

You must be logged in to post a comment.