Sysinternal Suit
  Name: NIRAV PAREKH Branch: M.TECH-CYBER SECURITY AND INCIDENT RESPONSE (SEM-I) i Sysinternals Suit What is Sysinternals Suit and what does it contain?    The Sysinternals utilities offer a powerful, convenient way to knock out all kinds of Windows tasks.      Sysinternals has been around for quite some time and was acquired by Microsoft in 2006. These are great little tools for getting some heavy-hitting Windows things done and sometimes done better than when using the built-in tools for a task. The entire suite of  products is available free for download.    Windows Sysinternals  is a part of the Microsoft TechNet website which offers technical resources and utilities to manage, diagnose, troubleshoot, and monitor a Microsoft Windows environment.Originally, the Sysinternals website (formerly known as ntinternals ) was created in 1996 and was operated by the company Winternals Software LP .      Here below is the screenshot of the different utilities in the Sysinternal suit.   Figure 1  Name: NIRAV PAREKH Branch: M.TECH-CYBER SECURITY AND INCIDENT RESPONSE (SEM-I) ii Understanding the Sysinternal Suit in detail: 1.   Accesschk: Accesschk is a console program. It shows which user has permissions to use the applications. Which users are using the different services or having the access on the services also it gives the details of the registry used by the different users and is  permissions. What are the global objects available and who can access them. Below screenshot shows the files that has integrity level.  Figure 2 2.   Accessenum: While the flexible security model employed by Windows NT-based systems allows full control over security and file permissions, managing permissions so that users have appropriate access to files, directories and Registry keys can be difficult. There's no built-in way to quickly view user accesses to a tree of directories or keys.  AccessEnum gives  Name: NIRAV PAREKH Branch: M.TECH-CYBER SECURITY AND INCIDENT RESPONSE (SEM-I) iii you a full view of your file system and Registry security settings in seconds, making it the ideal tool for helping you for security holes and lock down permissions where necessary. Below is the screenshot of its usage. Figure 3 3.   Autoruns: Simply run Autoruns and it shows you the currently configured auto-start applications as well as the full list of Registry and file system locations available for auto-start configuration. Autostart locations displayed by Autoruns include logon entries, Explorer add-ons, Internet Explorer add-ons including Browser Helper Objects (BHOs), Appinit DLLs, image hijacks, boot execute images, Winlogon notification DLLs, Windows Services and Winsock Layered Service Providers. Switch tabs to view autostarts from different categories.   Name: NIRAV PAREKH Branch: M.TECH-CYBER SECURITY AND INCIDENT RESPONSE (SEM-I) iv Figure 4 4.   Bginfo: When you run BGInfo it shows you the appearance and content of its default desktop  background. If left untouched it will automatically apply these settings and exit after its 10 second count-down timer expires. Selecting any button or menu item will disable the timer, allowing you to customize the layout and content of the background information. By placing BGInfo in your Startup  folder, you can ensure that the system information being displayed is up to date each time you boot. Once you've settled on the information to be displayed, use the command-line option /timer:0 to update the display without showing the dialog box.

