12

, , . , , Microsoft Windows.

, Windows .


,

Windows, , . . - , / . , , . .

Windows 10:

, - , , . , , (, ).

Windows . - , , / . Windows. , .

Windows 10:

. Windows. , .

:

, .

, . , . Microsoft Windows, fork(), . , , .

, . , .

! Windows .

, , , . , . - . , , (orphan process). . .

:

, , (PID) , , , . Microsoft Windows Resource Monitor , , .

Windows 10:

, Microsoft Windows, RAMMap, Windows Sysinternals Microsoft.

, RAMMap:

RAMMap

, RAMMap . , :

  RAMMap

, . , .


Windows

=

, , () , . . , , , , , .

Windows , SSD. Windows . .

, , () .

, :

  • Windows . . .
  • . , :

  • . , :

. -. Windows 10 .

Windows , .


Windows

Windows , (registry). . Windows , . () , , , . . HKEY_LOCAL_MACHINE\SYSTEM.

Windows:

  • HKEY_CLASSES_ROOT (HKCR): Windows. , .
  • HKEY_CURRENT_USER (HKCU): . , .
  • HKEY_LOCAL_MACHINE (HKLM): , .
  • HKEY_USERS (HKU): .
  • HKEY_CURRENT_CONFIG (HKCC): .

Registry Editor (regedit) Windows.

Windows:

, , . , , , .

. , LastWrite, . , . , - AutoRun. , , , .

, :

  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
  • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit]
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]

, Windows , [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] - "Notepad"="c:\windows\notepad.exe"


Windows Management Instrumentation

Windows . Windows . Windows Management Instrumentation (WMI) - , Windows, Windows .

WMI - Windows, Windows, . , .

WMI Windows, :

  • Computer Management ( ) Windows 10/Server 2019.
  • .
  • WMI .

WMI:

    WMI

Windows (WMI) . WMI SMB (RPCS) . RPCS 135.

WMI WMI command-line (WMIC). - wmic process call create.

WMI , .


Windows , . Performance Monitor, , Resource Monitor. ( ) - , Windows 10, Windows Server. , , . .

Windows 10/Server 2019:

 Performance Monitor

, Windows, . , . , , 1 10, .

Windows 10:

   Windows

, . , , , . , , , -.


Windows - , . , - Event Viewer. Event Viewet , .

, . , . 4 :

  • Security \ -
  • Application \ -
  • Setup \ -
  • System \ -

Windows (Event Viewer):

, , , . :

, , , , .

- 4624. Windows. 4625. , : , , , (, , , ), , ID .

Windows, /Security ( 7):

  • 4725 -
  • 4723 -
  • 4724 -
  • 4720\4726 - \
  • 4648 -
  • 4698 -
  • 4697 -
  • 4688\4689 - \

50% Merion Academy