home.social

#sysinternals — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sysinternals, aggregated by home.social.

  1. Practical intro to Windows Sysinternals, 2026-04-16, 12:00

    How to find out if you have malware on your #Windows system? Today we learn to use #Sysinternals, an alternative to the standard Task Manager. There will be a brief overview of ways #malware can hide and gain persistent access over reboots, and then a mini #CTF where you can find hidden "malware" on a virtual machine. Can you find all the secrets?

    Open for all, no registration needed. Bring a friend!

    More info: uu.se/en/department/informatio

  2. CW: На днях появился BlueHammer — опубликованный прототип уязвимости нулевого дня в Windows-системах. Позволяет повысить права (привелегии) в системе до уровня учётной записи SYSTEM или расширенных админских.
    Уязвимость нулевого дня оказалась опубликована вместе с протипом (примером) использования. Опубликовано человеком (Chaotic Eclipse), которому не удалось сообщить о проблеме через официальные каналы Microsoft, потому что соответствующее подразделение (MSRC) захотело прямо аж видео с подтверждением работоспособности данной уязвимости. Отказываясь иначе вести диалог и принимать информацию к сведению.

    Это тот апофеоз тотальной идиотии, который преобладает в Microsoft последние 10+ лет. Ниже расписано более детально по этой теме.
    Очередное дно пробито, но это не первый раз, а стабильность — это верный признак мастерства.
    Нет такого, что Linux или BSD-системы вдруг стали модными и популярными, это людям приходится уходить с Windows-систем из-за такого качества работы Microsoft.

    #bluehammer #microsoft #windows #cve #lang_ru @Russia

    RE: https://hub.hubzilla.de/item/fadba136-52e4-46e3-9101-5d8c7b0d61fb
  3. 🖥️ “Big Brother is Watching!” by Bartek Bielawski taught how to troubleshoot client machines remotely using #PowerShell without disrupting users: 🧰 #Sysinternals (Handle, Procmon, RAMMap) 📡 #pktmon > netsh 🧪 Smart prep = zero friction 🎟️ psconf.eu #RemoteSupport #PSConfEU

    - YouTube

  4. ----------------

    🛠️ Tool
    ===================

    Executive summary: The TrustedSec Sysmon Community Guide is an open-source reference that documents Microsoft Sysinternals Sysmon capabilities, event taxonomy, configuration guidance, and approaches for detection engineering. Authored and maintained by Carlos Perez of TrustedSec, the guide is published under a Creative Commons Attribution-ShareAlike 4.0 license.

    Technical details:
    • The guide catalogs Sysmon event families including process events (creation, termination, access), file events (create, delete, stream hash, create-time change), network events (network connections, DNS query), image loading, named pipes, driver loading, registry actions, create remote thread, raw access read, WMI events, clipboard capture, and process image tampering.
    • Platform-specific coverage includes the Sysmon kernel driver and Windows-focused internals as well as Linux support via sysinternalsEBPF that captures equivalent telemetry on Linux hosts.
    • Configuration and detection-engineering chapters provide conceptual approaches to crafting filters and detection rules, and the repository structure maps topics to chapter files (e.g., process-creation.md, network-connections.md).

    How it works (conceptual):
    • The guide describes how Sysmon produces structured event telemetry accessible to SIEMs, and how eBPF-based collectors on Linux mirror similar event classes.
    • Sample topics explain event fields used for correlation (process hashes, parent/child relationships, command line, network endpoints, registry keys) without prescribing a single configuration, acknowledging environment variability.

    Use cases:
    • Central reference for SOCs building Sysmon configurations and detection logic.
    • Baseline for threat hunting using process, file, and network indicators documented in the chapters.

    Limitations:
    • The guide emphasizes community contributions and does not prescribe one-size-fits-all configurations; specifics must be adapted per environment.
    • No vendor-specific deployment steps are included; the document focuses on capabilities and detection concepts.

    References: TrustedSec LLC, Carlos Perez, Creative Commons BY-SA 4.0. #sysmon #detection_engineering #sysinternals #eBPF #tool

    🔗 Source: github.com/trustedsec/SysmonCo

  5. An dieser Stelle sollte ich vielleicht mal 1 Schritt zurücktreten und resümieren, was passiert ist. Die Beiträge waren teils recht kleinteilig, obwohl ich nur das wichtigste notiert habe. Tatsächlich war das eine umfangreiche Analyse mit #winmerge #notepad++ #regedit #gpu-z #hwinfo #Sandboxie #sysinternals #DependencyWalker, #archiveorg unter Mithilfe von #ChatGPT und #perplexity Die beiden erzählen leider auch Mist und man muss genau hinschauen, aber ohne sie wäre das kaum machbar gewesen

  6. Der #Sysinternals System Monitor soll in Windows 11 integriert werden. techcommunity.microsoft.com/bl
    Vielleicht ist das der Grund, dass jetzt #Windows7 hinten runter fällt - schade.

    Zurück zu #KabyLake ich habe das mit #perplexityai und #ChatGpt diskutiert. Bei ersterem stößt man leider schnell an die Grenzen und dreht sich dann im Kreis. Mit ChatGpt (Basismodell) kann man erstaunlich tief in das Problem eindringen, aber es ist beileibe nicht alles richtig, was das Ding erzählt. Man muss hinschauen!

  7. 🖥️ “Big Brother is Watching!” by Bartek Bielawski taught how to troubleshoot client machines remotely using #PowerShell without disrupting users: 🧰 #Sysinternals (Handle, Procmon, RAMMap) 📡 #pktmon > netsh 🧪 Smart prep = zero friction 🎟️ psconf.eu #RemoteSupport #PSConfEU

    - YouTube

  8. 🖥️ “Big Brother is Watching!” by Bartek Bielawski taught how to troubleshoot client machines remotely using #PowerShell without disrupting users: 🧰 #Sysinternals (Handle, Procmon, RAMMap) 📡 #pktmon > netsh 🧪 Smart prep = zero friction 🎟️ psconf.eu #RemoteSupport #PSConfEU

    - YouTube

  9. Linus Torvalds and Bill Gates Meet for the First Time

    In a surprising turn of events, Microsoft co-founder Bill Gates and Linus Torvalds, the creator of the Linux kernel, recently met for the first time. The historic encounter took place at a dinner hosted by Sysinternals' creator Mark Russinovich.

    This rare moment brought together icons from Linux and Windows, with Microsoft’s Dave Cutler also meeting Torvalds for the first time. As Russinovich humorously noted in a LinkedIn post, “No major kernel decisions were made.” linkedin.com/posts/markrussino

    #Linux #LinuxKernel #Windows #BillGates #Linus #LinusTorvalds #MSFT #Microsoft #Tech #Technology #RareMoment #TechWorld #OperatingSystem #OS #Kernel #Sysinternals #DaveCutler

  10. Linus Torvalds and Bill Gates Meet for the First Time

    In a surprising turn of events, Microsoft co-founder Bill Gates and Linus Torvalds, the creator of the Linux kernel, recently met for the first time. The historic encounter took place at a dinner hosted by Sysinternals' creator Mark Russinovich.

    This rare moment brought together icons from Linux and Windows, with Microsoft’s Dave Cutler also meeting Torvalds for the first time. As Russinovich humorously noted in a LinkedIn post, “No major kernel decisions were made.” linkedin.com/posts/markrussino

    #Linux #LinuxKernel #Windows #BillGates #Linus #LinusTorvalds #MSFT #Microsoft #Tech #Technology #RareMoment #TechWorld #OperatingSystem #OS #Kernel #Sysinternals #DaveCutler

  11. Linus Torvalds and Bill Gates Meet for the First Time

    In a surprising turn of events, Microsoft co-founder Bill Gates and Linus Torvalds, the creator of the Linux kernel, recently met for the first time. The historic encounter took place at a dinner hosted by Sysinternals' creator Mark Russinovich.

    This rare moment brought together icons from Linux and Windows, with Microsoft’s Dave Cutler also meeting Torvalds for the first time. As Russinovich humorously noted in a LinkedIn post, “No major kernel decisions were made.” linkedin.com/posts/markrussino

    #Linux #LinuxKernel #Windows #BillGates #Linus #LinusTorvalds #MSFT #Microsoft #Tech #Technology #RareMoment #TechWorld #OperatingSystem #OS #Kernel #Sysinternals #DaveCutler

  12. Linus Torvalds and Bill Gates Meet for the First Time

    In a surprising turn of events, Microsoft co-founder Bill Gates and Linus Torvalds, the creator of the Linux kernel, recently met for the first time. The historic encounter took place at a dinner hosted by Sysinternals' creator Mark Russinovich.

    This rare moment brought together icons from Linux and Windows, with Microsoft’s Dave Cutler also meeting Torvalds for the first time. As Russinovich humorously noted in a LinkedIn post, “No major kernel decisions were made.” linkedin.com/posts/markrussino

    #Linux #LinuxKernel #Windows #BillGates #Linus #LinusTorvalds #MSFT #Microsoft #Tech #Technology #RareMoment #TechWorld #OperatingSystem #OS #Kernel #Sysinternals #DaveCutler

  13. Linus Torvalds and Bill Gates Meet for the First Time

    In a surprising turn of events, Microsoft co-founder Bill Gates and Linus Torvalds, the creator of the Linux kernel, recently met for the first time. The historic encounter took place at a dinner hosted by Sysinternals' creator Mark Russinovich.

    This rare moment brought together icons from Linux and Windows, with Microsoft’s Dave Cutler also meeting Torvalds for the first time. As Russinovich humorously noted in a LinkedIn post, “No major kernel decisions were made.” linkedin.com/posts/markrussino

    #Linux #LinuxKernel #Windows #BillGates #Linus #LinusTorvalds #MSFT #Microsoft #Tech #Technology #RareMoment #TechWorld #OperatingSystem #OS #Kernel #Sysinternals #DaveCutler

  14. EPISODE 10 - Scott & Mark Learn To... Zoomit with Scott Hanselman & Mark Russinovich | Wed at 12:15pm EST.

    youtube.com/watch?v=8WEoZ646Ikk

  15. Announcing ZoomIt v9.0 with LiveDraw and LiveZoom

    No more freezing before sketching/writing. Now you can write/draw on the Windows desktop & over applications that are actively moving on the screen.

    And it's still free! 😁

    techcommunity.microsoft.com/bl

    #SysInternals #Microsoft #Tools #windows

  16. Wprowadzenie do Sysinternals – PSTools/PsExec

    W pracy z systemami Windows kluczowy jest dostęp do narzędzi umożliwiających zdalną administrację. Choć nowoczesne rozwiązania, takie jak PowerShell Remoting, dobrze spełniają te funkcje, ich wykorzystanie często jest ograniczone przez polityki bezpieczeństwa lub rozwiązania EDR (Endpoint Detection & Response – wykrywanie i reagowanie w punktach końcowych). W takich sytuacjach można...

    #Narzędzia #Teksty #Narzędzia #Psexec #Pstools #Sysinternals #Windows

    sekurak.pl/wprowadzenie-do-sys

  17. Wprowadzenie do Sysinternals – PSTools/PsExec

    W pracy z systemami Windows kluczowy jest dostęp do narzędzi umożliwiających zdalną administrację. Choć nowoczesne rozwiązania, takie jak PowerShell Remoting, dobrze spełniają te funkcje, ich wykorzystanie często jest ograniczone przez polityki bezpieczeństwa lub rozwiązania EDR (Endpoint Detection & Response – wykrywanie i reagowanie w punktach końcowych). W takich sytuacjach można...

    #Narzędzia #Teksty #Narzędzia #Psexec #Pstools #Sysinternals #Windows

    sekurak.pl/wprowadzenie-do-sys

  18. Wprowadzenie do Sysinternals – PSTools/PsExec

    W pracy z systemami Windows kluczowy jest dostęp do narzędzi umożliwiających zdalną administrację. Choć nowoczesne rozwiązania, takie jak PowerShell Remoting, dobrze spełniają te funkcje, ich wykorzystanie często jest ograniczone przez polityki bezpieczeństwa lub rozwiązania EDR (Endpoint Detection & Response – wykrywanie i reagowanie w punktach końcowych). W takich sytuacjach można...

    #Narzędzia #Teksty #Narzędzia #Psexec #Pstools #Sysinternals #Windows

    sekurak.pl/wprowadzenie-do-sys

  19. Wprowadzenie do Sysinternals – PSTools/PsExec

    W pracy z systemami Windows kluczowy jest dostęp do narzędzi umożliwiających zdalną administrację. Choć nowoczesne rozwiązania, takie jak PowerShell Remoting, dobrze spełniają te funkcje, ich wykorzystanie często jest ograniczone przez polityki bezpieczeństwa lub rozwiązania EDR (Endpoint Detection & Response – wykrywanie i reagowanie w punktach końcowych). W takich sytuacjach można...

    #Narzędzia #Teksty #Narzędzia #Psexec #Pstools #Sysinternals #Windows

    sekurak.pl/wprowadzenie-do-sys