As I dive deeper into the world of cyber, I tend to quote my father about once a week, “If I knew then the things I know now!” I have been trying to share some of these worst kept secrets from time to time and here’s another one. A single tool that I can’t believe I lived without for so many years.
The tool’s name is…drumroll please…
WMIC.
If you already know about it, awesome. You’re legit. If not, learn about it right now and start to think about how you can use it. WMIC can query just about anything about your system and tell you what’s really going on.
Two commands in particular you should commit to memory right now:
wmic startup list full | more will show you every process that runs at startup. Hugely valuable for finding evil processes or even just troubleshooting performance.
wmic process list full | more is like task manager on steroids. And this command is a kernel-level command, so evil processes have to work harder to hide from it. There is one portion of this output that is just priceless. Look closely and notice the line “ParentProcessID.” It actually identities what process spawned each subsequent process. So, if you are suspicious about a particular process and find out that the parent process id is iexplore.exe, you might be on to something. Or maybe you find that the parent process id is explorer.exe, then it’s probably something you double clicked…DOH!
And YES, wmic can be used to query computers across the wire, just use the /node:%computername% switch. Wmic is extremely powerful and its usefulness is only limited by your imagination. But step one is knowing it exists! Now you can proceed to step 2.
The SANS Windows Commandline Cheat Sheet gives some more detail about this command and several others. Be sure to check it out.
What other commands do you know about that are under utilized or desperately in need of some more attention? Let us know in the comments below.
Thanks for reading and don’t forget to subscribe.
WMIC is great. Here’s a good reference for remote uninstalls. Its pretty easy to use separate lists of computers and I used it to check for bad software by piping out the name of the computer with the bad software to a network share .
http://community.spiceworks.com/how_to/179-using-a-command-line-to-uninstall-software-on-remote-pcs
Tra le novità che replica orologi Rolex propone nel mercato dell’orologeria, il primo orologio resistente all’acqua con datario e fuso orario e, soprattutto, il primo orologio ad essere certificato dal ricercatissimo cronometro. Rolex detiene ancora il record per il maggior numero di organismi di certificazione.
WOW! this article it really great i like it
Hey, i found a great site with so many games
Just click this >>> DetikToto <<<
The ninja sword‘s design and balance make it a weapon of elegant efficiency.
Interesting article! I had no idea about this Windows command. It’s amazing how many hidden features Windows has that can make tasks easier. Thanks for sharing this valuable tip—I’ll definitely be using it! http://www.kroger.com/feedback
The specific information about Basketball Stars is really valuable and useful for those who are passionate about basketball.