Home > Enterprise Desktop Tips > > Process Explorer 10.2: Client security aid
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Process Explorer 10.2: Client security aid


Serdar Yegulalp, Contributor
08.24.2006
Rating: -4.86- (out of 5)


Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


More Windows security tools

Windows security toolbox: Our experts' favorite freeware

Windows security toolbox: Free testing tools

There is a handful of free utilities for Windows that literally everyone needs to have -- and if I were running Microsoft these would be included as part of the operating system. One such utility is Process Explorer, Sysinternals' replacement for Task Manager. I've written before about PE and about the sheer number of genuinely useful features it has crammed into it, and I have resolved to keep people posted about major revisions to the program in case they aren't yet convinced.

As of this week, Process Explorer is now at version 10.2, and I wanted to provide a quick rundown of the new features and some ways it can be used to improve security.

  • Service permissions viewing and editing lets you inspect and change the permissions for running services. Many services throw failures because of unexpected permissions problems, so this is yet another way to debug that particular issue -- by seeing permissions in situ. You can also audit running services to determine if something is not supposed to be there -- for instance, a service that has been silently injected as part of an attack on a system.

  • Show New Processes option re-centers the display to show newly-launched processes in the Process window, so you can watch new processes being launched in a "hands-off" fashion. If you believe that illicit processes are being launched silently through some innocuous behavior (for instance, as part of a malware attack), this is a handy way to determine if it's true.

  • Many other DLL options are available, such as the ability to show pagefile-backed / unnamed sections in the DLL view; consolidated searching for DLLs and handles; more details in the DLL Properties dialog; optional highlighting for packed DLLs; DLLs that host SvcHost processes are shown in the Services tab along with regular services. You can use the "Verify" button in the DLL's Properties pane to determine if the image's signature matches its manufacturer -- one way to determine if a given component has been compromised with a bogus version. (Note that not all components are signed, but many crucial ones will be.)

  • My personal favorite new feature: The File menu now has a Runas command to let you quickly launch a process under different credentials. For quick access to running something in reduced privileges, the File menu also has a Run As Limited User function. You can perform quick-and-dirty "sandboxing" of applications this way, so if you have suspicions about an application you could run it in a constrained way first.

  • Support for 64-bit, both Itanium and AMD64 processors, and a signed 64-bit x64 driver for Windows Vista. Depending on which operating system you're running, you'll want to download the appropriate binary. If you want to "back-port" PE to Windows 9x/ME, there's a version for that as well. Also included are Vista-specific data such as the integrity level and virtualized processor information. If you're running Vista in beta form, try PE on it; it'll make for a nice way to get that much more familiar with the underpinnings of the OS.

  • There is more detailed I/O and memory-history information in the I/O/memory/CPU graphs.

  • Data from the Process, DLL and Handle views can all be copied easily to the Clipboard.

  • Handle view now has file object share flags, which indicate what available actions can be performed on a file that has been opened by a given process.

Serdar Yegulalp is editor of the Windows Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Patches, alerts and critical updates
Microsoft releases six patches for November
Structuring patch management in seven steps
Underlying causes of inconsistent patch management
Microsoft's Online Desktop Manager caters to small IT shops
Microsoft's Patch Tuesday brings a bumper crop of security fixes
Act fast with five critical September patches
Microsoft's August patches run the gamut
Patching third-party browsers adds more work in Windows shops
Troubleshooting Microsoft WSUS connectivity issues
Windows security tools for the busy desktop administrator

Microsoft Windows XP Pro
Guide to converting from Windows XP to Windows 7
Top 5 registry keys for Windows XP
Manage the desktop image lifecycle to limit work, ensure security
Secure Windows XP before a Windows 7 upgrade
Microsoft's August patches run the gamut
Hold on to Windows XP at your peril
XP stragglers blame hardware costs, new features
Your questions answered: The Windows 7 upgrade quandary
Windows Vista users get little pricing relief on Windows 7
Vista shops eye quick path to Windows 7, XP shops likely to resist

Endpoint security management tools
The right security tools for finding Windows desktop weaknesses
Using BitLocker in Windows 7
20 days to a more secure enterprise
How to get -- and keep -- user support with security
MDOP for Windows 7 available now
Microsoft's Online Desktop Manager caters to small IT shops
Monitoring user activity with network analyzers
Using third-party technologies with Microsoft's NAP
Understanding Microsoft's NAP's internal and external components
Microsoft's NAP can ensure security compliance

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts