Sysinternals & Windows CLI.
What's Already On The Box.
A static reference for the Sysinternals suite and the commands that ship with Windows itself. Nothing here needs an agent or a memory capture, just a single EXE or a shell you already have access to. Every flag below was checked against Microsoft's own Sysinternals documentation, not remembered from muscle memory. When live inspection isn't enough and a memory capture is possible, see Volatility3 Commands.
Sysinternals Suite
Fourteen tools, one EXE each, no installer. Flags marked with a dash are the ones worth memorizing — everything else is -? away.
| Tool | Purpose | Key Flags / Usage | Forensic Relevance |
|---|---|---|---|
| Process Explorer | Advanced Task Manager replacement: process tree, per-process handles/DLLs, live signature verification. | procexp /t /e launches elevated and minimizes straight to the tray. Otherwise UI-driven: Find > Find Handle or DLL (Ctrl+F). |
Spot a process spawned from a parent it has no business having, or trace a mutex/DLL straight to the process holding it, without waiting on a memory capture. |
| Process Monitor (Procmon) | Real-time file system, registry, process, and network activity logger with a filter engine. | procmon -accepteula -backingfile C:\cap.pml -quiet -minimized for a headless capture; -loadconfig cfg.pmc applies a saved filter set. |
Captures the actual sequence of writes, registry touches, and child processes a sample makes while it runs — ground truth a static read of the binary can't give you. |
| Autoruns / autorunsc.exe | Enumerates every location Windows will auto-execute from: Run keys, services, scheduled tasks, WMI subscriptions, Winlogon, and more. | autorunsc -a * -c -h -s -accepteula -nobanner — all locations, CSV output, hashes, signature verification. Add -m to hide signed Microsoft entries. |
The single highest-efficiency persistence hunt in the suite. Filter to unsigned, non-Microsoft entries first and work outward from there. |
| PsExec | Executes a process on a remote or local system over the admin share. | psexec \\host -u domain\user -p pass -s cmd runs as SYSTEM on the target; -c / -f copy the binary over first. |
A common lateral-movement tool in attacker hands. Its use leaves Event ID 7045 (a new service install) and a distinctive named pipe. |
| PsList | Command-line process listing with CPU, memory, and thread detail. | pslist -s 2 refreshes every 2 seconds like top; -x adds thread and memory detail; -t shows the tree. |
A no-GUI process snapshot for a machine you're triaging over a remote shell. |
| PsLoggedOn | Shows accounts logged on locally and via resource/share access. | psloggedon \\computer checks one system; psloggedon username checks every system that account is currently logged on to. |
Fastest way to find every machine a compromised account is logged into right now. |
| Handle | Lists open handles — files, registry keys, mutexes, sections — held by processes. | handle -a lists all handle types; handle -p 1234 scopes to one PID; handle somefile.exe finds every process holding that name open. |
Identify what's locking a file you need to image or delete, or hunt for a mutex name tied to a known malware family. |
| TCPView / tcpvcon | Live view of active TCP/UDP endpoints and their owning process; tcpvcon is the command-line build. | tcpvcon -a shows all endpoints, not just established connections; -c outputs CSV. |
Same job as netstat -ano, but resolves the owning process in one pass instead of a second tasklist lookup. |
| Sigcheck | Reports file version, timestamp, digital signature, hash, and optional VirusTotal detection for a file or directory. | sigcheck -e -h -s -u -vt c:\path — executables only, hashes, recurse, and with -vt, only files unknown to or flagged by VirusTotal. |
Batch-verify signatures across a directory to surface the one unsigned or VT-flagged binary sitting next to hundreds of legitimate ones. |
| Strings | Extracts printable ASCII and Unicode strings from any binary. | strings -n 8 file.exe sets an 8-character minimum length to cut short-garbage noise. |
The fastest first pass on an unknown binary — IPs, URLs, mutex names, and error text often surface before you ever open a disassembler. |
| ListDLLs | Lists DLLs loaded by running processes, including load path and version. | listdlls pid scopes to one process; listdlls -d dllname reverses the lookup across every process; -r flags relocated DLLs. |
The reverse lookup (-d) is the fast way to find every process a malicious DLL got sideloaded into. |
| AccessChk | Reports effective permissions on a file, registry key, service, process, or kernel object for a given account. | accesschk -w -u username path shows only write-access entries; -k targets a registry key instead of a file path; -s recurses. |
Confirm whether a low-privileged account can actually write to a path you suspect was used for persistence, instead of assuming from the ACL alone. |
| LogonSessions | Lists active logon sessions on the system. | logonsessions -p also lists the processes running under each session. |
Ties a logon session, and its logon time and type, directly to the processes it spawned — useful for scoping one interactive or RDP session. |
| WinObj | Browses the Windows Object Manager namespace directly: Device, GLOBAL??, BaseNamedObjects, and the rest. | GUI-only, no command-line switches. | When Handle or a YARA hit references a named object, WinObj is where you see it live in the namespace instead of trusting the string alone. |
Native Windows CLI Forensics
Nothing to install. The PowerShell rows run natively on Windows 10/11 and Server 2016+, cmdlets in, structured objects out — no text-parsing required.
| Command | What It Shows | Forensic Use Case |
|---|---|---|
tasklist /svc |
Running processes with the services hosted inside each one. | Ties a suspicious svchost.exe PID back to the actual service DLL running inside it. |
wmic process get processid,parentprocessid,name,commandline |
Full process list including command line and parent PID. | Recovers a process's launch arguments and parent chain without opening Process Explorer. wmic is deprecated on current Windows builds — prefer Get-Process or Get-CimInstance Win32_Process where available. |
netstat -ano |
Active TCP/UDP connections and listening ports with owning PID. | Chain straight into tasklist /svc or Get-Process to identify what's behind a suspicious outbound connection. |
systeminfo |
OS build, install date, hotfix list, uptime, and hardware summary. | Establishes OS baseline and patch level fast; an install date that doesn't match the asset's known deployment date is a finding on its own. |
reg query |
Dumps values under one registry key. Common persistence targets:reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"reg query "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"reg query "HKLM\SYSTEM\CurrentControlSet\Services"reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell
|
Checks the classic autostart locations directly, without waiting on Autoruns. |
schtasks /query /fo LIST /v |
Full detail on every scheduled task, including the actual command and trigger. | Scheduled tasks are one of the top three persistence mechanisms; /v surfaces the "Task To Run" field attackers hide there. |
net user / net localgroup administrators |
net user lists local accounts, net user <name> shows last logon and account flags; net localgroup administrators lists local admin membership. |
Catches an account added to local admins that shouldn't be there. |
wmic qfe list |
Installed hotfixes and patches with KB number and install date. | Confirms whether the patch for a known-exploited CVE is actually installed, and flags a hotfix installed suspiciously close to the incident window. wmic is deprecated on current Windows; prefer Get-HotFix where PowerShell is available. |
quser |
Logged-on users on the local or a remote session host, with session state and idle time. | Quick check for an active RDP or console session under an account that shouldn't be logged in right now. |
whoami /priv |
Privileges held by the current token. | Confirms whether a shell you're sitting in actually holds SeDebugPrivilege, SeImpersonatePrivilege, and similar, before assuming a privilege-escalation path is closed. |
Get-Process |
PowerShell process listing as real objects, pipeable into Where-Object / Sort-Object. |
Get-Process | Where-Object {$_.Path -notlike "C:\Windows*"} isolates binaries running outside expected directories in one line. |
Get-NetTCPConnection |
Object-based equivalent of netstat -ano: State, OwningProcess, LocalPort, and RemoteAddress as real properties. |
Get-NetTCPConnection -State Established | Select LocalAddress,RemotePort,OwningProcess pipes straight into Get-Process for one-line triage. |
Get-WinEvent |
Structured Event Log query across classic and modern ETW-based channels. | Get-WinEvent -FilterHashtable @{LogName='Security';Id=4688} for process-creation events, or query Microsoft-Windows-Sysmon/Operational when Sysmon is installed. |
Get-ScheduledTask |
Scheduled tasks as real objects — Actions, Triggers, State, Author — instead of parsed schtasks text. |
Get-ScheduledTask | Where-Object {$_.State -eq 'Ready' -and -not $_.Author} spots tasks with no signed author, a common persistence tell. |
Triage Patterns
Four combinations that show up in almost every live-response session, regardless of what actually brought you to the box.
Autoruns For Persistence Hunting
autorunsc -a * -c -h -s -m sweeps every autostart location in one run and drops straight to CSV. Filter to unsigned, non-Microsoft entries first — that's usually a handful of rows out of hundreds, and it's where the persistence mechanism is sitting.Procmon For Behavior Capture
netstat + tasklist For Connection-To-Process Triage
netstat -ano gives you the PID on a suspicious connection; tasklist /svc or Get-Process ties that PID to a name and, if it's svchost, the actual service running inside it. Two commands, no tools to install, works over almost any remote shell.reg query For The Classic Persistence Locations
reg query against Run/RunOnce, HKLM\SYSTEM\CurrentControlSet\Services, and Winlogon's Shell value covers the locations attackers reach for first. Slower than Autoruns for a full sweep, but it's the version you can run with nothing but a native shell.