Objectives
Objectives
3.2.11
Dia: Martes
Hora: N3-N6 Grupo: 008
PERIODO: Agosto-Diciembre
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 1 of 9 www.netacad.com
Part 2: Exploring Threads and Handles
Part 3: Exploring Windows Registry
Required Resources
• 1 Windows PC with internet access
Instructions
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 2 of 9 www.netacad.com
Lab - Exploring Processes, Threads, Handles, and Windows Registry
d. To locate the web browser process, drag the Find Window's Process icon into the opened web browser
window. Microsoft Edge was used in this example.
e. The Microsoft Edge process can be terminated in the Process Explorer. Right-click the selected process
and select Kill Process. Click OK to continue.
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 3 of 9 www.netacad.com
Lab - Exploring Processes, Threads, Handles, and Windows Registry
What happened to the web browser window when the process is killed? Se Cierra la Ventana del navegador
e. As you review the list of active processes, you find that the child process conhost.exe may be suspicious.
To check for malicious content, right-click conhost.exe and select Check VirusTotal. When prompted,
click Yes to agree to VirusTotal Terms of Service. Then click OK for the next prompt.
f. Expand the Process Explorer window or scroll to the right until you see the VirusTotal column. Click the
link under the VirusTotal column. The default web browser opens with the results regarding the malicious
content of conhost.exe.
g. Right-click the cmd.exe process and select Kill Process.
What happened to the child process conhost.exe? Se
termina el proceso porque el secundario depende del
principal
d. Click OK to continue.
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 4 of 9 www.netacad.com
Lab - Exploring Processes, Threads, Handles, and Windows Registry
e. Open the Process Explorer. Navigate to the folder where you have downloaded SysInternals. Open the
folder SysInternalsSuite > Open procexp.exe.
When you open the Process Explorer, what did you see?
El cuadro de diálogo de Contrato de licencia de explorador de procesos
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 5 of 9 www.netacad.com
Lab - Exploring Processes, Threads, Handles, and Windows Registry
Capturas
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 6 of 9 www.netacad.com
Lab - Exploring Processes, Threads, Handles, and Windows Registry
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 7 of 9 www.netacad.com
Lab - Exploring Processes, Threads, Handles, and Windows Registry
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 8 of 9 www.netacad.com
Lab - Exploring Processes, Threads, Handles, and Windows Registry
© 2018 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 9 of 9 www.netacad.com