3.1 Process Inspection with Process Hacker

Process Hacker (http://processhacker.sourceforge.net/) is an open source, multi-purpose tool that helps in monitoring system resources. It is a great tool for examining the processes running on the system and to inspect the process attributes. It can also be used to explore services, network connections, disk activity, and so on.

Once the malware specimen is executed, this tool can help you identify the newly created malware process (its process name and process ID), and by right-clicking on a process name and selecting Properties, you will be able to examine various process attributes. You can also right-click on a process and terminate it.

The following screenshot shows Process Hacker listing all the processes  running on the system, and the properties of wininit.exe:

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.17.154.171