How to use Windows SysInternals Tools

This is a short video of only 25 minutes but it will give you a very good idea about a Tool which is very effective yet most people do not know about it . It used to be called Pstools and later renamed to Sysinternals when Microsoft acquired it .These are some very good tools which can be used for Malware analysis and DFIR related activities .It can also be used for System/Network related troubleshooting .
Special Thanks to Syed Hasan who put lot of time and efforts in creating this short video for you . We do hope that you will find it very useful.

Video Breakdown for the Tools discussed in the video is given below.

00:00 – 02:26 What is Microsoft’s Sysinternals
02:27 – 05:25 ProcessExplorer
05:26 – 08:33 Procmon
08:34 – 10:42 Sysmon
10:43 – 12:45 AutoRuns
12:47 – 13:58 PsExec
13:59 – 15:20 TcpView
15:21 – 17:53 PsLoggedOn, LogonSessions
17:54 – 20:07 sDelete (Secure Delete)
20:08 – 22:57 Sigcheck
22:58 – 25:57 Streams

Tools can be downloaded from Microsoft SysInternals Page  .

 

Posted on: 01/09/2021

Name: Syed Hasan

Syed Hasan has considerable experience with major SIEM solutions like IBM's QRadar, Microsoft's Azure Sentinel, and AV's USM, EDR solutions like VMWare's Carbon Black and CrowdStrike Falcon, and Cloud Security Solutions like AWS GuardDuty. He is also part of an Incident Response team with sufficient experience in Host Forensics and Cloud Forensics in order to respond to threats in a timely manner. As part of his forensics experience, he has good experience in malware analysis, with continuing focus on reverse-engineering malware.