Process Utilities Flashcards

1
Q

What is Process Explorer used for?

A

as an advanced task manager and process analyzer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Process Explorer allow admins to do?

A

examine running processes, their dependencies, handles, DLLs, and more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How is Process Explorer helpful to threat hunters/incident responders?

A

helpful for identifying suspicious or malicious processes and their behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Autoruns used for?

A

view detailed information about autostart entries and manage them on a Windows system (manage and control what runs automatically)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are autostart entries on a Windows system?

A

programs, scripts, drivers, and services that automatically launch when the operating system starts or when a user logs in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Process Monitor (Procmon) used for?

A

real-time monitoring and detailed logging of system and process activity on Windows systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which tool can be used to trace the sequence of events leading to errors or unexpected behavior?

A

Procmon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How can be Procmon used to identify malware and suspicious activity?

A

helps spotting unusual or unauthorized file, registry, and network operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which tool can be used to see which processes are making network connections and the details of those connections?

A

Procmon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is PsExec used for?

A

execute processes and run commands on remote computers in a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What kind of remote administrative tasks can be done with PsExec?

A
  • running system utilities and diagnostic tools
  • installing or updating software
  • managing services and processes
  • configuring network settings
  • initiating remote command shells (cmd.exe) for interactive sessions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which tool will show temporary files or registry modifications that malware creates, for example, files or registry keys created and then removed during the life of the malware execution?

A

Procmon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What kind of process details does Process Explorer allow admins to inspect?

A
  • associated services
  • invoked network traffic
  • handles such as files or directories opened
  • DLLs and memory-mapped files loaded
How well did you know this?
1
Not at all
2
3
4
5
Perfectly