Sysinternals
1. handle
usage: handle [[-a [-l]] [-v|-vt] [-u] | [-c <handle> [-y]] | [-s]] [-p <process>|<pid>] [name] [-nobanner]
-a Dump all handle information.
-l Just show pagefile-backed section handles.
-c Closes the specified handle (interpreted as a hexadecimal number).
You must specify the process by its PID. Requires administrator
rights.
WARNING: Closing handles can cause application or system instability.
-g Print granted access.
-y Don't prompt for close handle confirmation.
-s Print count of each type of handle open.
-u Show the owning user name when searching for handles.
-v CSV output with comma delimiter.
-vt CSV output with tab delimiter.
-p Dump handles belonging to process (partial name accepted).
name Search for handles to objects with <name> (fragment accepted).
-nobanner Do not display the startup banner and copyright message.
No arguments will dump all file references.
列出进程打开的文件
handle -p chrome
File and Disk Utilities
AccessChk
AccessEnum
CacheSet
Contig
Disk2vhd
DiskExt
DiskMon
Disk Usage
DiskView
EFSDump
LDMDump
MoveFile
NTFSInfo
PendMoves
RegMon
SDelete
Sigcheck
Streams
Sync
VolumeID
Networking Utilities
Active Directory Explorer
Insight for Active Directory
AdRestore
PipeList
PsFile
PsPing
ShareEnum
TCPView
Whois
Process Utilities
AutoRuns
Handle
ListDLLs
Portmon
ProcDump
Process Explorer
Process Monitor
PsExec
PsGetSid
PsKill
PsList
PsService
PsSuspend
PsTools
ShellRunas
VMMap
Security Utilities
Autologon
LogonSessions
NewSID
PsLoggedOn
PsLogList
RootkitRevealer
Sysmon
System Information
ClockRes
Coreinfo
LiveKd
LoadOrder
ProcFeatures
PsInfo
RAMMap
WinObj
Miscellaneous
BgInfo
BlueScreen Screen Saver
CpuStres
Ctrl2Cap
DebugView
Desktops
Hex2dec
NotMyFault
PsPasswd
PsShutdown
RDCMan
RegDelNull
Registry Usage
Reghide
RegJump
Strings
Testlimit
ZoomIt
https://learn.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite