1,155 questions with Sysinternals-related tags

Sort by: Updated
0 answers

Sysmon service - security descriptors and recover options

To prevent user tampering and recover from process crashes, when installing sysmon I used to modify the security descriptors on the service to remove Admin's ability to stop it and set the recovery options to restart after 1st, 2nd and subsequent…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-09-19T19:51:35.4433333+00:00
Gary Portnoy 0 Reputation points
0 answers

How to temporarily stop as much as possible Microsoft network traffic on a potentially compromised machine

I need to connect my potentially compromised Win10 machine to the network briefly to determine any attempted target endpoint addresses, while blocking the actual connections at the edge firewall. However, various Microsoft products are generating an…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,500 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,892 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-09-19T14:35:05.7066667+00:00
BRiddle52 1 Reputation point
2 answers

Delete the white line and the logo

So I have just signed in my Microsoft Teams school's account and I found out when I press "Type here to search", up on the "All" is the white line with my school's logo. How can I remove this? Please tell me because I feel like I am…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,500 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-09-18T15:48:45.3666667+00:00
Kevin Wade 0 Reputation points
answered 2024-09-19T07:00:56.6733333+00:00
Karlie Weng 18,111 Reputation points Microsoft Vendor
6 answers

400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer"

On one specific server I have 400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer" (both picture taken on the same screenshot, so at the exact same time). What can be the cause of this…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2022-10-07T08:24:13.33+00:00
Bertrand K 51 Reputation points
answered 2024-09-18T04:43:46.6033333+00:00
office365 0 Reputation points
1 answer

"Autologon SysInternals" app is not working after enrolling the device in Intune

Our customer uses "Autologon SysInternals" app to enable autologon with saved password for some the devices. Once we enroll such device in Intune, "Autologon SysInternals" app fails its purpose and autogon with save password in not…

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,885 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,351 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,992 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2023-09-28T11:50:20.4133333+00:00
MITHILESH KUMAR 5 Reputation points
answered 2024-09-13T15:10:33.42+00:00
Stephen Bounds 0 Reputation points
1 answer One of the answers was accepted by the question author.

How to make way for powershell to run a script when error 15100 is in the way?

In order to run a script from https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_scripts?view=powershell-7.4 (the Get-servicelog.ps1) it is needed the error with McpManagementService be addressed (see…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,500 questions
Office Management
Office Management
Office: A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.Management: The act or process of organizing, handling, directing or controlling something.
2,125 questions
PowerShell
PowerShell
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,468 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-08-28T12:00:13.06+00:00
Claus Debanker 41 Reputation points
commented 2024-09-12T05:52:49.8433333+00:00
Jiajing Hua-MFST 9,425 Reputation points Microsoft Vendor
1 answer

Can't uninstall Sysmon 15.5 - access denied

Hello, I've tried multiple suggestions of other posts, nothing worked. When I try to uninstall sysmon using the same installer used to install it, I get: Stopping the service failed: The system cannot find the file specified Deleteervice failed: …

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,484 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-09-09T20:23:32.8766667+00:00
chivaz 1 Reputation point
commented 2024-09-12T01:09:04.3966667+00:00
S.Sengupta 18,636 Reputation points MVP
1 answer

autoruns shows MS file bthhfenum.sys not verified (Windows 10 Home)

When I run autoruns, it shows a file that is not verified that is supposed to be provided from microsoft. VirusTotal does not consider it a threat. Is this something I should be concerned about? My Windows 10 home edition is up to date. …

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2022-04-29T23:00:57.813+00:00
Tossed Salad 11 Reputation points
commented 2024-09-11T10:36:37.9233333+00:00
Bernd E 0 Reputation points
0 answers

Sysmon's reported CommandLine adds extra percent characters on Process Create events

When launching a process with a percent sign in the command line arguments, Sysmon adds an additional percent character for each one in the actual command line arguments. This issue is observed in both v13.24 and Sysmon 15.15 on at least Windows 10. For…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-08-31T17:11:27.5866667+00:00
Dave Schob 0 Reputation points
commented 2024-09-10T00:49:01.8366667+00:00
Dave Schob 0 Reputation points
0 answers

Accessibility of Microsoft Applications

Hi Community, I have been facing an issue with the accessibility settings on my mobile device for some of the microsoft apps like authenticator, defender, link to windows and launcher. When I turn the access on for them after some time it is turned back…

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
6,649 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
194 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-09-06T14:22:27.5433333+00:00
sid 45 Reputation points
edited the question 2024-09-07T12:51:50.8366667+00:00
sid 45 Reputation points
4 answers

Process information missing from network connection events

I'm verifying my Sysmon-configuration file with test scripts inspired by Atomic Red Team. When testing my NetworkConnect-rules (Event ID 3), one of my scripts are using wget from GnuWin32. Checking the result I saw that the event logged doesn't…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2021-06-01T11:09:17.32+00:00
Michael_N 961 Reputation points
answered 2024-09-05T11:13:50.8166667+00:00
Trevor Maliro 0 Reputation points
0 answers

Resize and align Process Explorer tool bar graphs

I think it would be very nice if all mini graphs in the tool bar of Sysinternals' Process Explorer were of equal size by default. They could/should use the total available width and automatically be resized when the window is resized. Please also include…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-09-01T09:18:17.9633333+00:00
Henkus Tancus Sapiens 0 Reputation points
0 answers

Autoruns 14.11 dark mode has black text instead of white/gray text on Windows 11

The screenshot below shows black text while Autoruns 14.11 is in dark mode on Windows 11. Ideally, the text should be white or gray while in dark mode. Can someone please look into this issue and provide a resolution?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-09-01T03:00:11.7766667+00:00
StevenJS 0 Reputation points
commented 2024-09-01T06:35:52.3533333+00:00
Viorel 116.7K Reputation points
1 answer

Autoruns looks bad in 4K

Try running Autoruns on a 4K monitor, or any other HDPI display. You will almost not be able to read the entries.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2020-12-14T16:19:18.437+00:00
Martijn 1 Reputation point
answered 2024-09-01T02:46:14.3866667+00:00
StevenJS 0 Reputation points
0 answers

One value in registry the dvr_fsebehavior is prone to discard its set value for other than the default; what can bind it in place?

hi, it is highly important the value to remain at (2) not at default (1). Safety cooperates with bcdedit/set to permit fullscreen modes without risk of physical impact which can be extreme gradually & imperceptibly. However the value is discarded of…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,500 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-08-09T07:12:53.8266667+00:00
Claus Debanker 41 Reputation points
commented 2024-08-30T12:09:50.6766667+00:00
Claus Debanker 41 Reputation points
2 answers

How to address system faults in relation to storage I/O issues which debilitate user experience?

Hi, I mean to query these faults in Events becuase they are esteemed relevant to errors with a storage disk, namely the events 154, 157, and 51. By backing up the disk and formatting it, then re-writing the data back to it, these faults below were…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,500 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-08-20T07:35:51.6566667+00:00
Claus Debanker 41 Reputation points
answered 2024-08-30T06:56:03.1733333+00:00
Claus Debanker 41 Reputation points
1 answer

Trying to find out what is uninstalling a program

Hi Team, I've been trying to install a program onto a managed pc and everything installs fine but a minute later the program will be deleted or uninstalled. I've ran Process Monitor and trying to find out what is uninstalling it, and it looks like the…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-08-27T06:45:11.5266667+00:00
Aaren Agushi 0 Reputation points
commented 2024-08-30T03:25:28.8433333+00:00
Aaren Agushi 0 Reputation points
2 answers

New startup registry key in Windows 10/11, NOT captured within autoruns

Hi All, While researching the startup behavior of Windows Container (Windows Metro) Apps , like the ones installed through Microsoft Store or native to System (xbox/phone, etc), I came across a new registry key location (different from the known…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2022-10-17T07:21:39.64+00:00
Rahat Sanghoi 6 Reputation points
edited a comment 2024-08-27T12:31:49.0433333+00:00
Julio Rodriguez 0 Reputation points
0 answers

Sysmon tries to connect to internet

Sysmon64.exe tried to connect to two hosts 192.229.221.95 and 152.199.19.74 According to whois services they are belongs to EDGECAST network. Is that normal behavior?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-08-27T04:40:36.8633333+00:00
ALEX 0 Reputation points
1 answer One of the answers was accepted by the question author.

Autoruns latest version not detecting scheduled tasks on windows 11

Windows 10 detects them fine all as it should

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
asked 2024-08-25T12:58:38.9833333+00:00
Stefan Scicluna 20 Reputation points
commented 2024-08-25T15:43:02.2633333+00:00
Stefan Scicluna 20 Reputation points