Skip to content

Sysinternals

Microsoft suite of tools for troubleshooting and analyzing Windows systems.

When I Use It

  • Live analysis of a suspicious Windows host, especially one without EDR
  • Reviewing every autostart location on a host for persistence
  • Watching what a suspicious program does in a lab VM

Installation

Common Tasks

Tool Use
Process Explorer Process tree with command lines, loaded DLLs, handles, signatures, and VirusTotal lookups
Process Monitor Real-time file system, registry, process, and network activity
Autoruns Every autostart location: Run keys, services, scheduled tasks, drivers, WMI, and more
TCPView Network connections mapped to processes
Sigcheck File version, signature, and hash details, with optional VirusTotal checks
Strings Readable strings from binaries: strings -a file.exe > strings.txt
ProcDump Dump process memory: procdump.exe -ma <PID>
Sysmon Detailed event logging; see Sysmon

Reading the Output

  • In Autoruns, Options -> Hide Microsoft Entries and Options -> Scan Options -> Check VirusTotal.com leave a short list of third-party and unknown entries to review
  • In Process Explorer, unsigned processes, processes running from user folders, and unusual parents are the first to check
  • Process Monitor captures a lot; set filters (process name, operation) before capturing, not after

Resources