Normal Windows Processes Flashcards
Knowing normal Windows processes to determine outliers
List the normal Windows Processes
System.exe
smss. exe
wining. exe
runtimebroker. exe
taskhostw. exe
winlogon. exe
csrss. exe
service. exe
svchost. exe
lsaiso. exe
lsass. exe
Describe system.exe
Responsible for most kernel-mode threads.Modules run under system.exe are primarily drivers.
Parent process of system.exe
None
Number of instances of system.exe
1
Describe smss.exe
Session manager process is responsible for new creating new sessions.
Parent process of smss.exe
System.exe
Number of instances of smss.exe
1 master instance and another child instance. Child instance exits after creating their session.
Describe wininit.exe
Starts key background processes within session 0. It starts services.exe, lsass.exe and lsaiso.exe
Parent process of wininit.exe
smss.exe
Number of instances of wininit.exe
1
Describe runtimebroker.exe
Acts as a proxy between Universal Windows Platform applications and the full Windows API.
Parent process of runtimebroker.exe
svchost.exe
Number of instances of runtimebroker.exe
1 or more
Describe taskhostw.exe
Generic host process for Windows Tasks.
Parent process of taskhostw.exe
svchost.exe