Jump to content
Aerosol

Windows Exploratory Surgery With Process Hacker

Recommended Posts

Posted

What Is Process Hacker?

Process Hacker is a free, open source, graphical tool for managing 32-bit and 64-bit Microsoft

Windows processes, services, threads, memory, handles, modules, Security Access Tokens

(SATs) and network connections. It is a wonderful tool for analyzing and combating malware,

understanding low-level details of the Windows operating system, troubleshooting, and

experimenting with Windows in ways which Microsoft never intended.

Process Hacker is similar to the famous Sysinternals Process Explorer tool from Microsoft, but

open source and a bit more fun (http://www.microsoft.com/sysinternals). Now that Process

Explorer is the property of Microsoft Corporation, Process Explorer cannot be enhanced with

features which might be used to circumvent security restrictions or otherwise embarrass

Microsoft. There are also no legal hassles when redistributing Process Hacker or its source code

(no Microsoft lawyers = good thing). Examining the source code of Process Hacker is an

interesting way to learn more about Windows internals, and Process Hacker itself is an actively

maintained project.

Fortunately, if you prefer Process Explorer, almost all of this presentation applies to it as well.

So please feel free to use Process Hacker or Process Explorer as you wish. Both tools are great.

And if you have questions, don't forget about the discussion forums for Process Hacker

(Process Hacker Forums - Index page) and Sysinternals Process Explorer

(Sysinternals Forums).

Read more: http://alexandreborgesbrazil.files.wordpress.com/2014/01/process_hacker_sans_jason_fossen.pdf

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...