Working with Process Explorer
Once we understand what processes are in the operating system, we will want to see them on our endpoint, in order to gather antivirus research leads.
To see a list of processes running on the operating system, we will use the Process Explorer tool (https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer), which will provide us with a lot of relevant information about the processes that are running in the operating system:
In Figure 2.4, you can see a list of the processes that are currently running in the Windows operating system, with a lot of other relevant information.
In order to conduct the research in the right way, it is important to understand the data provided by Process Explorer. From left to right, we can see the following information:
- Process – the filename of the process with its icon
- CPU – the percentage of CPU...