Sysinternals

1. handle

usage: handle [[-a [-l]] [-v|-vt] [-u] | [-c <handle> [-y]] | [-s]] [-p <process>|<pid>] [name] [-nobanner]
  -a         Dump all handle information.
  -l         Just show pagefile-backed section handles.
  -c         Closes the specified handle (interpreted as a hexadecimal number).
             You must specify the process by its PID. Requires administrator
             rights.
             WARNING: Closing handles can cause application or system instability.
  -g         Print granted access.
  -y         Don't prompt for close handle confirmation.
  -s         Print count of each type of handle open.
  -u         Show the owning user name when searching for handles.
  -v         CSV output with comma delimiter.
  -vt        CSV output with tab delimiter.
  -p         Dump handles belonging to process (partial name accepted).
  name       Search for handles to objects with <name> (fragment accepted).
  -nobanner  Do not display the startup banner and copyright message.

No arguments will dump all file references.

列出进程打开的文件

handle -p chrome

File and Disk Utilities

AccessChk
AccessEnum
CacheSet
Contig
Disk2vhd
DiskExt
DiskMon
Disk Usage
DiskView
EFSDump
LDMDump
MoveFile
NTFSInfo
PendMoves
RegMon
SDelete
Sigcheck
Streams
Sync
VolumeID

Networking Utilities

Active Directory Explorer
Insight for Active Directory
AdRestore
PipeList
PsFile
PsPing
ShareEnum
TCPView
Whois

Process Utilities

AutoRuns
Handle
ListDLLs
Portmon
ProcDump
Process Explorer
Process Monitor
PsExec
PsGetSid
PsKill
PsList
PsService
PsSuspend
PsTools
ShellRunas
VMMap

Security Utilities

Autologon
LogonSessions
NewSID
PsLoggedOn
PsLogList
RootkitRevealer
Sysmon

System Information

ClockRes
Coreinfo
LiveKd
LoadOrder
ProcFeatures
PsInfo
RAMMap
WinObj

Miscellaneous

BgInfo
BlueScreen Screen Saver
CpuStres
Ctrl2Cap
DebugView
Desktops
Hex2dec
NotMyFault
PsPasswd
PsShutdown
RDCMan
RegDelNull
Registry Usage
Reghide
RegJump
Strings
Testlimit
ZoomIt

https://learn.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite

posted @ 2023-05-10 13:13  fndefbwefsowpvqfx  阅读(16)  评论(0编辑  收藏  举报