Even in the most recent version of Windows, the Sysinternals tooling is as useful as ever. This collection of tools provides unique insight into valuable aspects of the operating system including: file and disk, networking, process, security, system, and more.
Typical uses for these tools include:
- Displaying detailed process and system information — with the Process Explorer
- Capturing low-level system events — with the Process Monitor
- Verifying the digital signatures of files and running programs (and of the modules loaded in those programs)
- Inspecting permissions of files, keys, services, shares, and other objects
- Monitoring security-relevant events across your network — with Sysmon
- Generating memory dumps when a process meets specified criteria
- Executing remote processes and closing remotely opened files
- Managing Active Directory objects and tracing LDAP API calls
- Capturing detailed data on processors, memory, and clocks
- Troubleshooting unbootable devices, file-in-use errors, unexplained communication, and other issues
But since the complete scope of Sysinternals is too large for a single post, this article will focus on one specific tool I found particularly handy.
Handle (a feature of the Process Utilities suite)
As the name suggests, this utility displays open handle information for any process in the system.
As a developer, have you ever encountered a situation where a process couldn’t write on a specific file? Here’s an example:
So at this point you’re trying to figure out which process(es) still hold a reference to that resource, right? Sometimes the answer isn’t obvious, even once the usual suspects have been ruled out. This is when a tool like Handle comes in handy. Use it to see which programs have a file open, or to view the object types and names of all handles in a program. It’s a lightweight command line tool and very fast. Its counterpart GUI app, Process Explorer, is also included in Sysinternals.
Sysinternals Suite: https://download.sysinternals.com/files/SysinternalsSuite.zip
Handle can run by typing “Handle” at the command prompt, but only by an administrator.
usage: handle [[-a] [-u] | [-c <handle> [-l] [-y]] | [-s]] [-p <processname>|<pid>> [name]
Once you’ve identified the process or process id(s), it’s easy to take appropriate action.
- Handle: https://docs.microsoft.com/en-us/sysinternals/downloads/handle
- Process Utilities: https://docs.microsoft.com/en-us/sysinternals/downloads/process-utilities
- Sysinternals: https://docs.microsoft.com/en-us/sysinternals/
Is your organization embarking on a digital application transformation? If so, countless technologies and tools must be considered. For help envisioning your transformation, please feel free to reach out. We’d love to assist in your journey.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
|cookielawinfo-checbox-analytics||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".|
|cookielawinfo-checbox-functional||11 months||The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".|
|cookielawinfo-checbox-others||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.|
|cookielawinfo-checkbox-necessary||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".|
|cookielawinfo-checkbox-performance||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".|
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.