TechEd 2010: Process Explorer, Process Monitor, PsExec TechEd 2011: Autoruns, Disk2Vhd, ProcDump, BgInfo, AccessChk TechEd 2012: “Gems” (Procmon.

Slides:



Advertisements
Similar presentations
This course is designed for system managers/administrators to better understand the SAAZ Desktop and Server Management components Students will learn.
Advertisements

Processes and Threads Chapter 3 and 4 Operating Systems: Internals and Design Principles, 6/E William Stallings Patricia Roy Manatee Community College,
TechEd 2010: Process Explorer, Process Monitor, PsExec TechEd 2011: Autoruns, Disk2Vhd, ProcDump, BgInfo, AccessChk TechEd 2012: “Gems” (Procmon tricks,
Planning Server Deployments
MCTS GUIDE TO MICROSOFT WINDOWS 7 Chapter 10 Performance Tuning.
How to use Sysinternals tools to troubleshoot SharePoint/Office
© Neeraj Suri EU-NSF ICT March 2006 Budapesti Műszaki és Gazdaságtudományi Egyetem Méréstechnika és Információs Rendszerek Tanszék Zoltán Micskei
Hands-On Microsoft Windows Server 2003 Administration Chapter 10 Monitoring and Troubleshooting Windows Server 2003.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 11: Monitoring Server Performance.
Chapter 14 Chapter 14: Server Monitoring and Optimization.
Chapter 11 - Monitoring Server Performance1 Ch. 11 – Monitoring Server Performance MIS 431 – created Spring 2006.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 8: Implementing and Managing Printers.
MCITP Guide to Microsoft Windows Server 2008 Server Administration (Exam #70-646) Chapter 14 Server and Network Monitoring.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 7: Advanced File System Management.
1 Chapter Overview Managing Compression Managing Disk Quotas Increasing Security with EFS Using Disk Defragmenter, Check Disk, and Disk Cleanup.
Check Disk. Disk Defragmenter Using Disk Defragmenter Effectively Run Disk Defragmenter when the computer will receive the least usage. Educate users.
VMware vCenter Server Module 4.
Hands-On Microsoft Windows Server 2008 Chapter 11 Server and Network Monitoring.
Windows Server 2008 Chapter 11 Last Update
Windows Server 2008 Chapter 6 Last Update
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
1 Chapter Overview Monitoring Server Performance Monitoring Shared Resources Microsoft Windows 2000 Auditing.
Windows 2000 Memory Management Computing Department, Lancaster University, UK.
Chapter-4 Windows 2000 Professional Win2K Professional provides a very usable interface and was designed for use in the desktop PC. Microsoft server system.
Introduction to HP LoadRunner Getting Familiar with LoadRunner >>>>>>>>>>>>>>>>>>>>>>
MODERN OPERATING SYSTEMS Third Edition ANDREW S. TANENBAUM Chapter 11 Case Study 2: Windows Vista Tanenbaum, Modern Operating Systems 3 e, (c) 2008 Prentice-Hall,

Tutorial 11 Installing, Updating, and Configuring Software
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
MCTS Guide to Microsoft Windows Vista Chapter 11 Performance Tuning.
MCTS Guide to Microsoft Windows 7
Hands-On Virtual Computing
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 7: Advanced File System Management.
Chapter 6 Configuring Windows Server 2008 Printing
5 Chapter Five Web Servers. 5 Chapter Objectives Learn about the Microsoft Personal Web Server Software Learn how to improve Web site performance Learn.
Copyright 2000 eMation SECURITY - Controlling Data Access with
Ch 6. Performance Rating Windows 7 adjusts itself to match the ability of the hardware –Aero Theme v. Windows Basic –Gaming features –TV recording –Video.
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 11: Monitoring Server Performance.
Windows XP to Windows 7 using P2V Migration. Agenda Deploying Local P2V Migration for SA Retro Mode Scripts Customize MDT 2010 with Disk2VHD Windows Virtual.
CMPF124 Personal Productivity with Information Technology Chapter 1 – Part 4 Introduction To Windows Operating Systems Basic Windows Admin Introduction.
Module 2 Part IV Introduction To Windows Operating Systems Basic Windows Admin Introduction To Windows Operating Systems Basic Windows Admin.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Four Windows Server 2008 Remote Desktop Services,
®® Microsoft Windows 7 for Power Users Tutorial 9 Evaluating System Performance.
1 Chapter Overview Creating Drive and Folder Shares Using Distributed File System Installing Network Printers Administering Network Printers Managing Share.
Week #3 Objectives Partition Disks in Windows® 7 Manage Disk Volumes Maintain Disks in Windows 7 Install and Configure Device Drivers.
1 Chapter Overview Performing Configuration Tasks Setting Up Additional Features Performing Maintenance Tasks.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 11: Monitoring Server Performance.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Chapter 10 System Monitoring Issues Performance Benchmarks NT Server Services Users and Server Access Information Task Manager for Applications Ram and.
Virtual techdays INDIA │ august 2010 Windows Sysinternals Primer: Process Explorer, Process Monitor & More Tools Aviraj Ajgekar │ Regional Site Manager.
Troubleshooting Security Issues Lesson 6. Skills Matrix Technology SkillObjective Domain SkillDomain # Monitoring and Troubleshooting with Event Viewer.
sysinternals demo sysinternals.
Page 1 Printing & Terminal Services Lecture 8 Hassan Shuja 11/16/2004.
The world leader in serving science Overview of Thermo 21 CFR Part 11 tools Overview of software used by multiple business units within the Spectroscopy.
Process Description and Control Chapter 3. Source Modified slides from Missouri U. of Science and Tech.
CSC190 Introduction to Computing Operating Systems and Utility Programs.
Unit 4: Processes, Threads & Deadlocks June 2012 Kaplan University 1.
CITA 171 Section 1 DOS/Windows Introduction. DOS Disk operating system (DOS) –Term most often associated with MS-DOS –Single-tasking operating system.
Planning Server Deployments Chapter 1. Server Deployment When planning a server deployment for a large enterprise network, the operating system edition.
Managing Server 2012 Lecture 3 Lecturer: Dr. Simon Tran Course: IT 442.
SQL Database Management
bitcurator-access-webtools Quick Start Guide
Malware Incident Response
TechEd /22/2018 8:39 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
MCTS Guide to Microsoft Windows 7
Windows Processes and Services
Process Description and Control
bitcurator-access-webtools Quick Start Guide
Presentation transcript:

TechEd 2010: Process Explorer, Process Monitor, PsExec TechEd 2011: Autoruns, Disk2Vhd, ProcDump, BgInfo, AccessChk TechEd 2012: “Gems” (Procmon tricks, nerd-out on TS sessions/winsta/desktops, LogonSessions, DU) TechEd 2013: What’s New/Updated Since the Book

{

Autologon RegJump MoveFile PendMoves

Main window: Heat map for CPU, commit, working set, and GPU columns (new!) New highlight color for “immersive” apps Suspended processes say “Suspended” in the CPU column Tooltips: tasks in Win8 Taskhostex processes; Win8 app package names Process context menu: “create dump” creates 32-bit dumps for 32-bit processes (new!); background priority (which sets the CPU, memory and I/O priorities of a process to Low). New columns: GPU usage and memory, Win8 app package name, paged pol, non-paged pool, Autostart location, process timeline Find dialog: reports types of items found. Process Details: Image tab: Win8 ASLR types, Autostart location + Explore to (DLL property dialog too) Security tab: Win8 AppContainer and Capability SIDs, LSA logon session ID, sortable columns, view protected processes Services tab: restart Threads: show stacks of.NET processes DLL View: Autostart column, property GPU support: utilization and memory monitoring (Vista+) Modern color scheme

Bookmarks: Toggle with Ctrl+B Navigate with F6, Shift+F6 Saved in PML log files Convert Highlight filters to Include filters Navigate highlighted events with F4, Shift+F4 Process Start events capture current directory and environment variables Support for Windows 8 control codes

New autostart locations “Jump to image” Timestamp of image file Highlights suspicious images (unsigned, no company name or description) Active filter in the status bar Better support for browsing folders on WinPE File association for *.ARN files Better reporting of targets of shortcuts, Rundll32 and other host executables AutorunsC: switches for file hashes and for autostarts for all users AutorunsC: reports Authenticode SHA1 and SHA256 hashes

PsExec 2.0 (not yet released): adds [-r servicename] PsPasswd: book version released Oct 2011 (new syntax for domain accounts) PsPing: new utility!

VMMap Shows the ASLR status of image regions Shows “unusable” virtual memory regions Timeline shows commit usage instead of working set ProcDump Three major updates, four minor updates (!!!) DebugView Book describes 4.77 (published Sept 2011) with big syntax changes Captures output generated by “modern apps” on Windows 8 Option /q to terminate a running instance. (Not yet released) LiveKd -m option (“mirror dump”) captures a fully-consistent kernel dump of a running system Support for Windows 8 Supports newer Intel processors that implement the XSAVE instruction ListDLLs -v option dumps full file version information including signatures -u option reports only unsigned DLLs Handle Updated to match Process Explorer’s new driver

“Client”  “Agent” “Server  “Viewer” Ver 4.76Ver 4.82

VMMap Shows the ASLR status of image regions Shows “unusable” virtual memory regions Timeline shows commit usage instead of working set ProcDump Two major updates, five minor updates (!!!) DebugView Book describes 4.77 (published Sept 2011) with big syntax changes Captures output generated by “modern apps” on Windows 8 Option /q to terminate a running instance. (Not yet released) LiveKd -m option (“mirror dump”) captures a fully-consistent kernel dump of a running system Support for Windows 8 Supports newer Intel processors that implement the XSAVE instruction ListDLLs -v option dumps full file version information including signatures -u option reports only unsigned DLLs Handle Updated to match Process Explorer’s new driver

SigCheck -i now reports detailed certificate information For unsigned PE images, the embedded link date is reported instead of file system date Returns exit code that can be used in scripts (0 for all signed, 1 if any not signed) Reports Authenticode SHA256 hashes AccessChk -l option shows more security descriptor detail, including object owner and flags Reports Windows 8 claims and capabilities in token contents Includes RemoteInteractive in access rights Prefixes AppContainer SIDs with “Package\” SDelete Meanings of –z and –c swapped (book is correct)

SigCheck v1.70 shows signed file SigCheck v1.91 shows signed file SigCheck v1.70 shows unsigned program file SigCheck v1.91 shows unsigned program file

BgInfo Reports Windows 8 (not yet released!) Desktops Compatible with Windows 8 ZoomIt Configure for autostart Specify initial default zoom level Disable animation

Strings -f option specifies file offset at which to start scanning Disk Usage (DU) -c and -ct options to print output as CSV Additional data with CSV -u option to count each instance of a hardlinked file

Contig Supports defragmentation of NTFS metadata files, including the MFT More detailed fragmentation analysis reporting -f option to analyze free space fragmentation -l option to set data length for quick file creation

Whois -v option prints verbose information about domain registration referrals

RU: new utility! RAMMap Command line options to scan to a file and to import from a saved file; creates a file association. Support for Windows 8 and for systems with more than 16GB RAM. CoreInfo New command line options: -f reports only core feature information -v reports only virtualization-related features (requires admin rights on Intel systems) Support for many additional features, including: hardware- assisted virtualization, SLAT, SMAP, RDSEED, BMI1, ADX, HLE, RTM, INVPCID, RDRAND, LAHF/SAHF, Prefetchw, Intel Speedstep, hyperthreading support on AMD multicore systems, TSC (timestamp counter) Invariant support, Microsoft’s SLAT term for Intel’s Extended Page Table, and AMD’s Nested Paging virtualization features.

New utility, released March 27 Shows per-key registry usage Helps find registry bloat Syntax identical to that of DU

Process Explorer, Process Monitor, and PsExec Autoruns, Disk2Vhd, ProcDump, BgInfo and AccessChk "Gems"

Sysinternals web site Sysinternals blog (announces updates) Mark Russinovich’s blog: Windows Sysinternals Administrator’s Reference Russinovich/dp/ X