Troubleshooting with the Windows Sysinternals Tools

Troubleshooting with the Windows Sysinternals Tools

$54.99

SKU: 9780735684447
Quantity Discount
5 + $41.24

Description

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and Windows expert Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.

Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:

  • Use Process Explorer to display detailed process and system information
  • Use Process Monitor to capture low-level system events, and quickly filter the output to narrow down root causes
  • List, categorize, and manage software that starts when you start or sign in to your computer, or when you run Microsoft Office or Internet Explorer
  • Verify digital signatures of files, of running programs, and of the modules loaded in those programs
  • Use Autoruns, Process Explorer, Sigcheck, and Process Monitor features that can identify and clean malware infestations
  • Inspect permissions on files, keys, services, shares, and other objects
  • Use Sysmon to monitor security-relevant events across your network
  • Generate memory dumps when a process meets specified criteria
  • Execute processes remotely, and close files that were opened remotely
  • Manage Active Directory objects and trace LDAP API calls
  • Capture detailed data about processors, memory, and clocks
  • Troubleshoot unbootable devices, file-in-use errors, unexplained communication, and many other problems
  • Understand Windows core concepts that aren’t well-documented elsewhere
  • Part I Getting started
  • Chapter 1 Getting started with the Sysinternals utilities
  • Chapter 2 Windows core concepts
  • Chapter 3 Process Explorer
  • Chapter 4 Autoruns
  • Part II Usage guide
  • Chapter 5 Process Monitor
  • Chapter 6 ProcDump
  • Chapter 7 PsTools
  • Chapter 8 Process and diagnostic utilities
  • Chapter 9 Security utilities
  • Chapter 10 Active Directory utilities
  • Chapter 11 Desktop utilities
  • Chapter 12 File utilities
  • Chapter 13 Disk utilities
  • Chapter 14 Network and communication utilities
  • Chapter 15 System information utilities
  • Chapter 16 Miscellaneous utilities
  • Part III Troubleshooting—“The Case of the
  • Chapter 17 Error messages
  • Chapter 18 Crashes
  • Chapter 19 Hangs and sluggish performance
  • Chapter 20 Malware
  • Chapter 21 Understanding system behavior
  • Chapter 22 Developer troubleshooting

The definitive guide to managing, troubleshooting, and diagnosing Windows clients and servers with the newest, most powerful Windows Sysinternals tools

  • Co-authored by Microsoft Fellow Mark Russinovich, creator of the Windows Sysinternals tools
  • Fully updated! Your authoritative guide to the latest versions of Process Explorer, Process Monitor, and 70 other powerful (and free!) Sysinternals tools
  • Expanded “Case of the Unexplained” section illustrates Sysinternals tools at work
  • New “Procmon and ProcDump, Better Together” feature demonstrates powerful tasks you can now perform by using both tools together

Mark Russinovich is Chief Technology Officer of Microsoft Azure, where he oversees the technical strategy and architecture of Microsoft’s cloud computing platform. He is a widely recognized expert in distributed systems, operating system internals, and cybersecurity. He is the author of the Jeff Aiken cyberthriller novels, Zero Day, Trojan Horse, and Rogue Code, and co-author of the Microsoft Press Windows Internals books. Russinovich joined Microsoft in 2006 when Microsoft acquired Winternals Software, the company he cofounded in 1996, as well as Sysinternals, where he authors and publishes dozens of popular Windows administration and diagnostic utilities. He is a featured speaker at major industry conferences, including Microsoft Ignite, Microsoft //build, RSA Conference, and more.

Aaron Margosis is a Principal Consultant with Microsoft’s Global Cybersecurity Practice, where he has worked with security-conscious customers since 1999. Aaron specializes in Windows security, least-privilege, application compatibility, and the configuration of locked-down environments. He is a top speaker at Microsoft conferences, and created many of the tools commonly used by organizations implementing high-security environments, including LUA Buglight, Policy Analyzer, IE Zone Analyzer, LGPO.exe (Local Group Policy Object utility), and MakeMeAdmin, which can be downloaded through his blog (https://blogs.msdn.microsoft.com/aaron_margosis) or through two team blogs for which he is a primary author (https://blogs.technet.microsoft.com/fdcc and https://blogs.technet.microsoft.com/SecGuide).

  • Process Explorer, Process Monitor, and 70 other powerful (and free!) utilities
  • Applicable to all technical roles on Windows, including hobbyists, developers, and researchers
  • Includes an expanded “Case of the Unexplained,” detailed coverage of new tools and updated features in existing tools, and a “Procmon and ProcDump, Better Together” feature demonstrating new capabilities that the tools now enable in each other

This Second Edition has been thoroughly updated to reflect new Sysinternals tools and updated features in existing tools. It contains an expanded “Case of the Unexplained” section illustrating these tools at work, and a new “Procmon and ProcDump, Better Together” feature demonstrating capabilities Procmon and ProcDump now enable in each other.

Optimize Windows system reliability and performance with Sysinternals

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and Windows expert Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.

Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:

  • Use Process Explorer to display detailed process and system information
  • Use Process Monitor to capture low-level system events, and quickly filter the output to narrow down root causes
  • List, categorize, and manage software that starts when you start or sign in to your computer, or when you run Microsoft Office or Internet Explorer
  • Verify digital signatures of files, of running programs, and of the modules loaded in those programs
  • Use Autoruns, Process Explorer, Sigcheck, and Process Monitor features that can identify and clean malware infestations
  • Inspect permissions on files, keys, services, shares, and other objects
  • Use Sysmon to monitor security-relevant events across your network
  • Generate memory dumps when a process meets specified criteria
  • Execute processes remotely, and close files that were opened remotely
  • Manage Active Directory objects and trace LDAP API calls
  • Capture detailed data about processors, memory, and clocks
  • Troubleshoot unbootable devices, file-in-use errors, unexplained communication, and many other problems
  • Understand Windows core concepts that aren’t well-documented elsewhere

Additional information

Dimensions 1.70 × 7.35 × 9.00 in
Series

Imprint

Format

ISBN-13

ISBN-10

Author

,

Subjects

sysinternals, error messages, pstools, procdump, autoruns, russinovich, technet, process monitor, process explorer, professional, Active Directory, H-39 MCRSFT PRESS DST AGR PRF, &nbsp, IT Professional, Employability, diagnostics, higher education, troubleshooting