Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 32 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Windows Command Line Tools For Security And Other Analysis
Ethical Hacker Community Forums
December 01, 2008, 11:05:12 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Windows Command Line Tools For Security And Other Analysis  (Read 1411 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: May 29, 2008, 01:33:09 PM »

Quick write-up by Larry Seltzer of PC Mag including a shoutout to Ed Skoudis' work and Sysinternals:

Quote
Hat tip to Bruce Schneier for pointing me to a couple of tip articles by Ed Skoudis on Windows command line tools, the first group to tell if your system has been hacked, and the second for more general system analysis.

I've written about this stuff myself before, but it's always good to have a refresher. If you use Windows every day, especially if you administer Windows systems, you do yourself a big favor by becoming expert in these tools.

Some examples:

wmic: The Windows Management Instrumentation Console is a command line way to do lots of system management you might normally do with a GUI, such as Device Manager stuff. You can also list all running processes and all startup processes.

net: Network configuration and information commands, like seeing who is connected to what, creating shares, and what groups people belong to.

find: Been around since DOS 2.0 I think, but it's still underutilized. A filter program that you can pass content through to find the interesting stuff.

Consider:
wmic process list brief | find "OUTLOOK"
which shows detail on the Outlook process.


What Skoudis doesn't get into is the fine collection of free tools from Sysinternals, now part of Microsoft. These tools are mostly GUI tools for deep system analysis and performance enhancement, and most of them are available as command line versions too.

My favorites:

Process Explorer: Extensive details on running processes, including constituent processes of services.

Filemon, Regmon: Monitor and report on file and registry activity in the system. These are famous and indispensable tools.

BGInfo: Show system information as part of your desktop background.

And the ultimate place you want to be to be a true wiz is to become proficient in scripting these command line tools with Windows Script Host. True there are other scripting products, but wscript is included in all versions of Windows. In this way you can quickly build programs to do powerful system functions.

Original post with links:
http://blogs.pcmag.com/securitywatch/2008/05/windows_command_line_tools_for.php

Don
Logged

CISSP, MCSE, CEH, Security+ SME
shakuni
Jr. Member
**
Offline Offline

Posts: 78


View Profile
« Reply #1 on: May 30, 2008, 01:56:24 AM »

When sysinternals originally published these tools, they came with source code but when Microsoft took over sysinternals all the source code dissappered. Now since we've started discussing programming concepts, if anyone needs the source codes to extend these tools or to understand how these tools works, then get them from the wayback machine (http://www.archive.org) or contact me.
Logged

There is no rule, law or tradition that apply universally... including this one.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.042 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.