TechNet
Products
IT Resources
Downloads
Training
Support
Products
Windows
Windows Server
System Center
Internet Explorer
Â
Office
Office 365
Exchange Server
Â
SQL Server
SharePoint Products
Lync
See all products »
Resources
Curah! curation service
Evaluation Center
Learning Resources
Microsoft Tech Companion App
Microsoft Technical Communities
Microsoft Virtual Academy
Script Center
Server and Tools Blogs
TechNet Blogs
Â
TechNet Flash Newsletter
TechNet Gallery
TechNet Library
TechNet Magazine
TechNet Subscriptions
TechNet Video
TechNet Wiki
Windows Sysinternals
Virtual Labs
Solutions
Networking
Cloud and Datacenter
Security
Virtualization
Updates
Service Packs
Security Bulletins
Microsoft Update
Trials
Windows Server 2012 R2
System Center 2012 R2
Microsoft SQL Server 2012 SP1
Windows 8.1 Enterprise
See all trials »
Related Sites
Microsoft Download Center
TechNet Evaluation Center
Drivers
Windows Sysinternals
TechNet Gallery
Training
Training Catalog
Class Locator
Microsoft Virtual Academy
Free Windows Server 2012 courses
Free Windows 8 courses
SQL Server training
e-Learning overview
Certifications
Certification overview
MCSA: Windows 8
Windows Server Certification (MCSE)
Private Cloud Certification (MCSE)
SQL Server Certification (MCSE)
Other resources
TechNet Events
Second shot for certification
Born To Learn blog
Find technical communities in your area
Support options
For small and midsize businesses
For enterprises
For developers
For IT professionals
From partners
Â
For technical support
Support offerings
For home users
More support
Microsoft Premier Online
Microsoft Fix It Center
TechNet Forums
MSDN Forums
Security Bulletins & Advisories
International support solutions
Log a support ticket
Not an IT pro?
Microsoft Customer Support
Microsoft Community Forums
Sign in
Sysinternals Site Discussion
Options
About
Email Blog Author
RSS for posts
Atom
OK
Search Blogs
Tags
AccessChk
AdExplorer
Autoruns
BgInfo
Coreinfo
DebugView
Disk2vhd
Handle
LiveKd
Mark Russinovich
Mark's blog
ProcDump
Process Explorer
process monitor
PsExec
RAMMap
Sigcheck
Strings
Sysinternals
TCPView
TechEd
Testlimit
VMMap
Webcast
ZoomIT
Archive
Archives
September 2014
(1)
August 2014
(2)
May 2014
(3)
March 2014
(1)
February 2014
(1)
January 2014
(2)
December 2013
(1)
November 2013
(1)
October 2013
(2)
August 2013
(1)
July 2013
(1)
June 2013
(2)
May 2013
(1)
March 2013
(1)
February 2013
(1)
January 2013
(3)
December 2012
(2)
November 2012
(1)
October 2012
(3)
September 2012
(1)
August 2012
(1)
July 2012
(2)
June 2012
(2)
May 2012
(2)
April 2012
(1)
March 2012
(1)
February 2012
(1)
January 2012
(1)
December 2011
(2)
November 2011
(1)
September 2011
(2)
August 2011
(2)
July 2011
(2)
May 2011
(2)
April 2011
(2)
March 2011
(1)
February 2011
(4)
January 2011
(4)
December 2010
(4)
November 2010
(5)
October 2010
(4)
September 2010
(4)
August 2010
(2)
July 2010
(3)
June 2010
(3)
May 2010
(4)
April 2010
(4)
March 2010
(3)
January 2010
(4)
December 2009
(1)
November 2009
(1)
October 2009
(7)
September 2009
(2)
August 2009
(3)
July 2009
(2)
June 2009
(3)
May 2009
(2)
April 2009
(3)
March 2009
(3)
February 2009
(2)
January 2009
(2)
December 2008
(2)
November 2008
(2)
October 2008
(3)
September 2008
(3)
August 2008
(3)
July 2008
(4)
June 2008
(2)
May 2008
(3)
April 2008
(3)
March 2008
(1)
February 2008
(5)
January 2008
(2)
December 2007
(1)
November 2007
(4)
October 2007
(3)
September 2007
(6)
August 2007
(3)
July 2007
(2)
June 2007
(2)
May 2007
(5)
April 2007
(6)
March 2007
(8)
February 2007
(2)
January 2007
(3)
December 2006
(2)
November 2006
(2)
October 2006
(1)
May 2006
(1)
August 2005
(1)
April 2005
(1)
January 2005
(1)
July 2004
(1)
April 2004
(1)
June 2003
(1)
February 2003
(1)
October 2002
(1)
August 2002
(1)
January 2002
(1)
August 2001
(1)
April 2001
(1)
November 2000
(1)
August 2000
(1)
June 2000
(1)
March 2000
(1)
January 2000
(1)
October 1999
(1)
August 1999
(1)
June 1999
(1)
May 1999
(1)
April 1999
(1)
Sysinternals Site Discussion
TechNet Blogs
»
Sysinternals Site Discussion
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Updates: Handle v4.0. Procdump v7.01, Procexp v16.04, Regjump v1.02, Autoruns v12.03
Posted
3 months ago
by
DK_Msft
Handle v4 : Handle is a command-line utility that can show which processes have a handle to a file or other resource open, or show all open handles. Version 4 now works with standard-user rights, allowing standard users to identify the handles open by...
Updates: Autoruns v12.02, Coreinfo v3.31, Sysmon v1.01, Whois v1.12
Posted
4 months ago
by
DK_Msft
Autoruns v12.02 : This fixes a bug that could cause Autoruns to crash on startup, updates the image path parsing for Installed Components to remove false positive file-not-found entries, and correctly reports image entry timestamps in local time instead...
New: Sysmon v1.0; Updates: Autoruns v12.01, Coreinfo v3.3, Procexp v16.03
Posted
4 months ago
by
safarr_msft1
Sysmon v1.0 : We’re excited to announce Sysmon, a new Sysinternals utility that monitors and reports key system activity via the Windows event log, including detailed information about process creation, network connections and file creation timestamp...
Mark's Latest Novel and TechEd Presentations Now Available
Posted
7 months ago
by
safarr_msft1
Mark's Latest Novel, Rogue Code : The third book in Mark’s Jeff Aiken technothriller series was published on May 20. In Rogue Code , Jeff is hired to penetration test the New York Stock Exchange. When he reaches the heart of the trading engine...
Updates: Autoruns v12.0, Procdump v7.0
Posted
7 months ago
by
safarr_msft1
Autoruns v12.0 : This release of Autoruns, a Windows application and command-line utility for viewing autostart entries, now reports the presence of batch file and executable image entries in the WMI database, a vector used by some types of malware. ...
Updates: AccessChk v5.2; PsExec v2.11; Sigcheck v2.1; VMMap v3.12
Posted
7 months ago
by
safarr_msft1
AccessChk v5.2 : This release of AccessChk, a security command-line utility that reports the effective access and permissions of files, registry keys, processes, and more, adds support for file and printer shares. In addition, it adds filtering options...
Updates: Process Explorer v16.02, Process Monitor v3.1, PSExec v2.1, Sigcheck v2.03
Posted
9 months ago
by
safarr_msft1
Process Explorer v16.02 : This minor update adds a refresh button to the thread’s stack dialog and ensures that the Virus Total terms of agreement dialog box remains above the main Process Explorer window. Process Monitor v.3.1 : This release...
Updates: Process Explorer v16.01, Sigcheck v2.02
Posted
10 months ago
by
safarr_msft1
Process Explorer v16.0 : This release fixes a bug that could cause a crash when the VirusTotal column is added to the process view, and another that could cause a crash when verifying digital signatures. Sigcheck 2.02 : This release fixes a bug that...
Updates: Process Explorer v16.0, PsPing v2.01
Posted
10 months ago
by
safarr_msft1
Process Explorer v16.0 : Thanks to collaboration with the team at VirusTotal, this Process Explorer update introduces integration with VirusTotal.com, an online antivirus analysis service. When enabled, Process Explorer sends the hashes of images and...
Updates: Disk2vhd v2.01, PsPing v2.0
Posted
11 months ago
by
safarr_msft1
Disk2vhd v2.01 : This update fixes a bug that could result in Disk2vhd crashing when converting to VHDX format and adds a command-line switch, -c, to have Disk2vhd use online copy instead of Volume Shadow Copy. PsPing v2.0 : This is a major release...
Updates: Coreinfo v3.21, Disk2vhd v2.0, LiveKd v5.31
Posted
over 1 year ago
by
safarr_msft1
Coreinfo v3.21 : CoreInfo is a command-line tool for reporting processor topology, NUMA performance, and processor features. The v3.21 release adds microcode reporting. Disk2vhd v2.0 : Disk2vhd, a utility for performing physical-to-virtual conversion...
Updates: RAMMap v1.32, Sigcheck v2.01
Posted
over 1 year ago
by
safarr_msft1
RAMMap v1.32 : This fixes a bug in v1.30 that caused RAMMap to fail on Windows 8. Sigcheck v2.01 : This update fixes a bug in the handling of the -u option that sometimes resulted in Sigcheck reporting signed files.
Update: RAMMap v1.31
Posted
over 1 year ago
by
safarr_msft1
RAMMap v1.31 : This update fixes a bug in v1.30 that caused RAMMap to fail on Windows 8.
Updates: PsExec v2.0, RAMMap v1.3, Sigcheck v2.0
Posted
over 1 year ago
by
safarr_msft1
PsExec v2.0 : PsExec, a popular utility for executing processes on remote systems, introduces a new option, -r, that specifies the name PsExec assigns to its remote service. This can improve performance when multiple users are interacting concurrently...
Autoruns v11.70, Bginfo v4.20, Disk2vhd v1.64, Process Explorer v15.40
Posted
over 1 year ago
by
safarr_msft1
Autoruns v11.70 : This release of Autoruns, a powerful utility for scanning and disabling autostart code, adds a new option to have it show only per-user locations, something that is useful when analyzing the autostarts of different accounts than the...
Update: Autoruns v11.62
Posted
over 1 year ago
by
safarr_msft1
Autoruns v11.62 : This release fixes a bug in version 11.61’s jump-to-image functionality.
Updates: Mark's TechEd Sessions, Autoruns v11.61, Strings v2.52, ZoomIt v4.5
Posted
over 1 year ago
by
kebal_msft1
Mark’s TechEd Sessions Available On-Demand : Mark delivered four top-rated sessions at Microsoft’s TechEd US conference two weeks ago, and the recordings are available now for on-demand viewing. In Windows Azure Infrastructure Services, he...
Updates: Autoruns v11.6, Procexp v15.31, Procmon v3.05, Sigcheck v1.92
Posted
over 1 year ago
by
kebal_msft1
Autoruns v11.6 : Autoruns is a utility for enumerating and disabling executables and DLLs configured to activate in dozens of autostart registration points. This update fixes some minor bugs and adds Authenticode SHA1 and SHA256 hash reporting to Autorunsc...
Updates: Accesschk v5.11, Procdump v6.0, RAMMap v1.22, Strings v2.51
Posted
over 1 year ago
by
safarr_msft1
AccessChk v5.11 : AccessChk, a command line utility for dumping the effective permissions and security descriptors for files, registry keys, processes, tokens, object manager objects, now prefixes Windows 8 application container SIDs with the word “Package”...
Updates: Autoruns v11.5, Du (Disk Usage) v1.5, Procdump v5.14, Procmon v3.04, Ru (Registry Usage) v1.0
Posted
over 1 year ago
by
safarr_msft1
Autoruns v11.5 : This update to Autoruns, a utility for managing autostarting applications and components, now reports the image timestamp of executables and the last-modified timestamp of other file types and autostart locations to help with forensic...
Updates: Pendmoves v1.2, Process Explorer v15.3, Sigcheck v1.91, Zoomit v4.42
Posted
over 1 year ago
by
safarr_msft1
Pendmoves v1.2 : This update to Pendmoves adds support for 64-bit directories. Process Explorer v15.3 : This major Process Explorer release includes heat-map display for process CPU, private bytes, working set and GPU columns, sortable security groups...
Update: Autoruns v11.42
Posted
over 1 year ago
by
safarr_msft1
Autoruns v11.42 : This release fixes a bug in the parsing of network file paths introduced in v11.41.
Updates: Autoruns v11.41, Handle v3.51, Movefile v1.01, Procdump v5.13, Sigcheck v1.9
Posted
over 1 year ago
by
safarr_msft1
Autoruns v11.41 : This Autoruns update reports the hosting image target of link shortcut references. Handle v3.51 : This minor update to Handle, a command-line utility that dumps process handle tables, fixes a bug in its file share drive letter formatting...
Updates: Autoruns v11.4, ProcDump v5.12, SDelete v1.61
Posted
over 1 year ago
by
safarr_msft1
Autoruns v11.4 : Autoruns v11.4 adds additional startup locations, fixes several bugs related to image path parsing, adds better support for browsing folders on WinPE, and fixes a Wow64 redirection bug. Procdump v5.12 : This Procdump update fixes a...
Update: ZoomIt v4.41
Posted
over 2 years ago
by
safarr_msft1
ZoomIt v4.41 : This update fixes a bug in ZoomIt v4.4 that prevented it from running on 32-bit Windows XP.
>
ZW5kZW5yYWhheXU5QGdtYWlsLmNvbQ==