A Penetration Testing Cheat Sheet For Windows Machine – Intrusion Detection
A Penetration Testing Cheat Sheet For Windows Machine – Intrusion Detection
Save Email
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Begin Learning Cyber Security for FREE Now!
FREE REGISTRATION Already a Member Login Here
In the event that your Windows machine has been compromised or for any
other reason, this cheat sheet is intended to help. This article is for Windows
Administrators and security personnel to better execute a thorough
examination of their framework (inside and out) keeping in mind the end goal
is to search for indications of compromise.
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
“Windows File Protection is not active on this system.”
“The protected System file [file name] was not restored to its
original, valid version because of the Windows File Protection…”
“The MS Telnet Service has started successfully.”
Look for a large number of failed logon attempts or locked out
accounts.
C:> eventvwr.msc
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
need to be familiar with normal processes and services and search for
deviations.
C:> taskmgr.exe
C:> tasklist
C:> services.msc
C:> sc query
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
C:> tasklist /svc
Check file space usage to look for sudden major decreases in free space, using
the GUI (right-click on a partition), or type:
C:> dir c:
Look for strange programs referred to in registry keys associated with system
start up:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
HKLMSoftwareMicrosoftWindowsCurrentVersionRunonce
HKLMSoftwareMicrosoftWindowsCurrentVersionRunonceEx
Note that you should also check the HKCU counterparts (replace HKLM with
HKCU above).
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Using the GUI:
C:> regedit
Look at file shares, and make sure each has a defined business purpose:
Look at which sessions this machine has opened with other systems:
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
C:> nbtstat –S
The –b flag shows the executable name and the DLLs loaded for the network
connection.
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Also, check Windows Firewall configuration:
Look for unusually scheduled tasks, especially those that run as a user in the
Administrators group, as SYSTEM, or with a blank user name.
C:> schtasks
Using the GUI, run msconfig and look at the Startup tab:
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Start –> Run, mscon g.exe
6.Unusual Accounts
C:> lusrmgr.msc
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Look for unusually sluggish performance and a single unusual process hogging
the CPU:
Look for unusual system crashes, beyond the normal level for the given
system.
On a periodic basis (daily, weekly, or each time you logon to a system you
manage,) run through these quick steps to look for anomalous behavior that
might be caused by a computer intrusion. Each of these commands runs
locally on a system.
Join
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Ready to share your knowledge and expertise?
Submit to 0P3N
10 Comments
INFOSECTDK
Log in to Reply
MASTERK
11:30 pm on April 2, 2017
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Thanks for your time.
Log in to Reply
A FAROOK
11:03 am on March 30, 2017
Great article
Log in to Reply
W@Y&3
Log in to Reply
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
THEDUDE
1:31 am on March 29, 2017
Log in to Reply
Page 2 of 2 « 1 2
Comment on This
You must be logged in to post a comment.
Related Reads
Cloud-Based A Penetration
Application Testing Cheat
December 6, 2016 7578 March 26, 2017 22402
By: Hari Charan By: gurubaran
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
OUR STUDENT SUPPORT CYBRARY|0P3N
REVOLUTION SUPPORT CYBRARY
We believe Cyber
Get charon223
Security training
Support What is the need of
should be free, for
secure and strong
everyone, FOREVER.
passwords?
Everyone, OTHER PAGES Views: 338 / October 8, 2019
everywhere, About
deserves the
Join Our Team rebeccaberis2
OPPORTUNITY to Donate Here to Get
Press PCI Security
learn, begin and This Month's Donor
Terms of Service Compliance
grow a career in Badge
Verify Certi cate Challenges and
this fascinating
Best Practices
eld. Therefore, Submit
Views: 427 / October 7, 2019
Cybrary is a free Suggestions
community where Companies
slwelty
people, companies
National
and training come
Cybersecurity
together to give
Awareness Month
everyone the ability Views: 1614 / October 4,
to collaborate in an 2019
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
FOLLOW US: a b c j
Protected by
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD