Windows_Forensics Flashcards
CHFI
-
This parameter displays the supported options and the units of measurement used for output values
-a
Displays all active TCP connections as well as the TCP and UDP ports on which the computer is listening
-e
Displays Ethernet statistics, such as the number of bytes and packets sent and received. This parameter can be combined with -s.
-l
This parameter is used to show only local logons instead of both local and network resource logons
-n
Displays active TCP connections. However, the addresses and port numbers are expressed numerically with no specified names.
-o
Displays active TCP connections and includes the process ID (PID) for each connection. Using the PID, the application can be found in the Processes tab in Windows Task Manager. This parameter can be combined with -a, -n, and -p.
-r
Displays the count of all NetBIOS names resolved by broadcast and by querying a Windows Internet Naming Service (WINS) server
-x
This parameter tells the command not to show logon times
/s Computer
Specifies the name or IP address of a remote computer (do not use backslashes)
/svc
Lists all the service information for each process without truncation
/u Domain \ User
Runs the command with the account permissions of the user specified by User or Domain\User
/v
Specifies that verbose task information be displayed in the output; it should not be used with the /svc or the /m parameter.
\<computer></computer>
This parameter specifies the name of the computer for which logon information is to be listed.
4728
A member was added to a security-enabled global group.
4730
A security-enabled global group was deleted.
4733
A member was removed from a security-enabled local group
4735
local group was changed