tool that can do the following things:
• TCP / UDP ports in use
• Software installed
• Services running,
• Administrative Accounts
• Processes running
To use this tool must be downloaded. Sysinternals suite
Then we have to download the toolkit MIR-ROR
And the application that will make us the dump.downloads
Everything we put in one folder.
For example I've put everything into C: \ Forensic
Now let's run the dump tool
Now we can see the file from console for example:
And now graphically,
In this way we will have an analysis of Windows.
................................................
herramienta que es capaz de hacer las siguientes cosas:
•Puertos TCP/UDP en uso
•Software instalado
•Servicios en ejecución,
•Cuentas administrativas
•Procesos en ejecución
Para utilizar esta herramienta hay que descargar.Sysinternals suite
Luego tendremos que descargar the toolkit MIR-ROR
Y la aplicación que nos hará el volcado.downloads
Todo lo hemos de poner en una misma carpeta.
Por ejemplo yo lo he puesto todo en C:\Forense
Ahora vamos a ejecutar la herramienta de volcado.
Ahora podemos ver el fichero desde consola por ejemplo:
Y ahora de manera gráfica,
De esta manera ya tendremos un análisis de Windows.




No hay comentarios:
Publicar un comentario