-
Notifications
You must be signed in to change notification settings - Fork 198
Finding Processes
Synopsis: Find a sample process for each logged in user
Mandatory Parameters: -
Optional Parameters: -
Examples:
(Tokens) > Sample_Processes
P/Invokes: OpenProcess, OpenProcessToken, CloseHandle, GetTokenInformation, GetTokenInformation
Synopsis: Find a sample process for each logged in user via WMI
Mandatory Parameters: -
Optional Parameters: -
Examples:
(Tokens) > Sample_Processes_WMI
P/Invokes: -
Synopsis: Find all processes associated with a user
Mandatory Parameters: Username
Optional Parameters: -
Examples:
(Tokens) > Find_User_Processes domain\user
P/Invokes: OpenProcess, OpenProcessToken, CloseHandle, GetTokenInformation, GetTokenInformation
Synopsis: Find all processes associated with a user via WMI
Mandatory Parameters: Username
Optional Parameters: -
Examples:
(Tokens) > Find_User_Processes_WMI domain\user
P/Invokes: -
Synopsis: List all desktop sessions, i.e. current interactive users
Parameters: -
Optional Parameters: -
Examples:
(Tokens) > Sessions
P/Invokes: WTSEnumerateSessions, WTSQuerySessionInformationW