Professional Documents
Culture Documents
Roll – 2041018
1. PSLIST
3. PSTREE
It displays the parent child process relationships by using the output from
the pslist and formatting it in a tree view.Since it relies on pslist it cannot
list the hidden and terminated process.
In the following output we can see that System is the parent process.
winlogon.exe is the child process of smss.exe and so on.
4. PSXVIEW
It displays the full path associated with a process. It is also used to list the
loaded modules(executable and DLLs).It gets the information about loaded
modules from a structure named the process environment block.
We can also check DLLs for a particular process. For ex- If we want to
check for process 592 then can use dlllist -p 592 as shown in the 3rd
output.
6. CONNECTIONS
And in the output we can also check which process is 2160 or 2392.
7. CONNSCAN
It displays which local address connected with which remote address and
which pid is responsible for that. We can also check which process this pid
belongs to. For example- for pid 944 we can check, but we found
something suspicious . We used other commands such as psscn , but not
able to know the process.