Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Sysinternals

Premium room

Learn to use the Sysinternals tools to analyze Windows systems or applications.

easy

90 min

57,136

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

What are the tools known as Sysinternals?

The Sysinternals tools is a compilation of over 70+ Windows-based tools. Each of the tools falls into one of the following categories:

  • File and Disk Utilities
  • Networking Utilities
  • Process Utilities
  • Security Utilities
  • System Information
  • Miscellaneous

The Sysinternals tools and its website (sysinternals.com) were created by Mark Russinovich in the late '90s, along Bryce Cogswell under the company Wininternals Software.

In 2006, Microsoft acquired Wininternals Software, and Mark Russinovich joined Microsoft. Today he is the of Microsoft Azure. 

Mark Russinovich made headlines when he reported that Sony embedded rootkits into their music CDs back in 2005. This discovery was made known thanks to one of the Sysinternals tools he was testing. You can read more about that here (opens in new tab).  

He also discovered in 2006 that Symantec was using rootkit-like technology. You can read more about that here (opens in new tab)

The Sysinternals tools are extremely popular among IT professionals who manage Windows systems. These tools are so popular that even red teamers and adversaries alike use them. Throughout this room, I'll note which tools  has identified to have been used by adversaries. 

The goal of this room is to introduce you to a handful of Sysinternals tools with the hopes that you will expand on this knowledge with your own research and curiosity.

Hopefully, you can add Sysinternals to your toolkit, as many already have. 

If you want to access the virtual machine via Remote Desktop (opens in new tab), use the credentials below. 

Machine IPMACHINE_IP

Useradministrator

Passwordletmein123!

Screenshot showing Remmina remote desktop preferences

Accept the Certificate when prompted, and you should be logged into the remote system now.

Note: The virtual machine may take up to 3 minutes to load.

Answer the questions below
When did Microsoft acquire the Sysinternals tools?

deployed the attached virtual machine and I'm ready to move on...

Ready to learn Cyber Security?

The Sysinternals room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.

Already have an account? Log in

We use cookies to ensure you get the best user experience. For more information see our cookie policy.