Professional Documents
Culture Documents
Ism Lab 3
Ism Lab 3
REG.NO : 20BCE0612
DATE : 09-02-2023
SYSINTERNAL TOOLS:
File and Disk Utilities:
1.AccessEnum:
Although the flexible security model used by Windows NT-based
systems allows full control over security and file permissions, managing
permissions so that users have appropriate access to
files, directories, and registry keys can be difficult. There is no built-in
way to quickly view a user's access to a directory or key
tree. AccessEnum gives you a complete view of your file system
and registry security settings in seconds, making it the perfect tool to
help you find security holes and lock down permissions if needed.
SAI ARAVIND RAJ S 20BCE0612
2.CacheSet:
CacheSet is an applet that allows you to manipulate the working set of
system file cache settings. Unlike CacheMan, CacheSet works with all
versions of NT and works unmodified with new service pack releases. In
addition to the ability to control the minimum and maximum working
set size, the cache's working set can be reset to scale as needed from
a minimum starting point. Also, unlike CacheMan, changes
made using CacheSet immediately affect the cache size.
Use CacheSet to tune system cache size performance in a way that
is not possible without setting internal variables like CacheMan.
memo. On NT 4.0 SP4 and later, to use CacheSets, you must have
the Increase Quotas permission (the Administrator account
has this permission by default). CacheSet has been updated
to include this permission to work with SP4.
SAI ARAVIND RAJ S 20BCE0612
3.Disk2vhd:
4.Diskview:
Network Utilities:
1.AD explorer
3.ShareEnum:
4.TCPview:
TCPView is a Windows program that displays a detailed list of all TCP
and UDP endpoints on your system, including local and remote
addresses and TCP connection status. On Windows Server 2008, Vista,
and XP, TCPView also reports the name of the process that owns the
endpoint. TCPView is a more informative and convenient subset of the
Netstat program that ships with Windows. The TCPView download
includes Tcpvcon, a command-line version with the same functionality.
SAI ARAVIND RAJ S 20BCE0612
Process Utilities:
AutoRun:
This utility, which has the most comprehensive knowledge of auto-
starting locations of any startup monitor, shows you what programs are
configured to run during system bootup or login, and when you start
various built-in Windows applications like Internet Explorer, Explorer and
media players. These programs and drivers include ones in your startup
folder, Run, RunOnce, and other Registry keys. Autoruns reports
Explorer shell extensions, toolbars, browser helper objects, Winlogon
notifications, auto-start services, and much more. Autoruns goes way
beyond other autostart utilities.
Autoruns' Hide Signed Microsoft Entries option helps you to zoom in on
third-party auto-starting images that have been added to your system
and it has support for looking at the auto-starting images configured for
other accounts configured on a system.
The download also includes a command-line Autorunsc that can output
in CSV format.
SAI ARAVIND RAJ S 20BCE0612
2.Portmon:
Portmon is a utility that monitors and displays all serial and
parallel port activity on a system. It has advanced filtering and
search capabilities that make it a powerful tool for exploring the
way Windows works, seeing how applications use ports, or
tracking down problems in system or application configurations.
3.Process Explorer
4.ProcessMonitor:
5.VMMap:
Besides flexible views for analyzing live processes, VMMap supports the
export of data in multiple forms, including a native format that preserves
all the information so that you can load back in. It also includes
command-line options that enable scripting scenarios.
Security Utilities:
1.Autologon
To turn off auto-logon, hit Disable. Also, if the shift key is held down
before the system performs an autologon, the autologon will be disabled
SAI ARAVIND RAJ S 20BCE0612
for that logon. You can also pass the username, domain and password
as command-line arguments:
System Information:
1.Rammap
2.WinObj:
Miscellaneous:
1.BGInfo:
2.DebugView:
Nessus:
SAI ARAVIND RAJ S 20BCE0612
SAI ARAVIND RAJ S 20BCE0612
SAI ARAVIND RAJ S 20BCE0612