DiamondCS 에서 제작된 Cmdline이라는 유용한 툴입니다.
Forensic에서 정보수집 할때도 사용되고 있으며, 모의해킹 점검할때도 간단한 정보들 확인할때 유용하게 쓰입니다.
http://www.diamondcs.com.au/consoletools.php
참고도서 : Malware Incident Response: Volatile Data on Windows Systems
SYSTEM:
CmdLine
CmdLine reveals the commandline parameters of all processes.
FolderMon
A powerful monitoring program that allows you to see all (or specific) file activity in a folder & subfolders, or even an entire drive!
DelayExec
DelayExec allows you to start programs in a pre-execution state of suspension, where the process is loaded but code isn't initially executed.
Procs
Complete process control - listing (with full paths and process IDs), terminating, and module enumeration.
Windows
Complete control over all parent and child windows, including listing and modification.
CPUInfo
Displays a variety of information about your processor(s). Multi-CPU support, detects serial number, speed, name, features and more.
Drivers
Lists all drivers on the system. Full image paths and base addresses are shown.
ErrorDesc
ErrorDesc converts any decimal or hexadecimal number (or range) into their respective error descriptions.
NETWORK:
OpenPorts
The powerful OpenPorts reveals which processes are behind the TCP and UDP network ports on your system.
HTTPGet
Download files from HTTP/FTP servers from the command line!
RemCache
Allows you to view and even remove individual cached webpages from Internet Explorer's cache.
Whois
Whois allows you to see important information about domain registrations, such as ownership and business information.
Adapters
Displays information about all network adapters. Details include MAC address, Description, IP addresses, DHCP info and more.
GetIP
Connects to the Internet to obtain your real Internet IP address.
EnumIPs
Displays all local IP addresses, including broadcast and net mask details.
USER INFO:
WhoAmI
Displays the current computer name, current user name, IP addresses, and Administrator status.
IsAdmin
Displays the current user name and determines if the user has Administrator privileges.
MS-DOS:
Note: These tools can be run from the Windows Command Prompt, or from MS-DOS (or emulator). More info
BIOSDump (MS-DOS)
View or save ROM images of your system BIOS (and BIOS extension ROMs) to files.
MemDump (MS-DOS)
MemDump allows you to read the entire conventional memory address space (0000:0000 - FFFF:FFFF).
FILE TOOLS:
FindAll
A fast and powerful tool for searching the contents of files. Supports Unicode, case (in)sensitivity, subdirectory searching and more.
StrDump
Scan a file for text strings - a quick, useful way to avoid sifting through 'junk' data.
HexDump
Dump the contents of any file in traditional 'hex dump' format.
MD5
Quickly and easily calculate strong 128-bit checksums from strings and files. (GUI version also available)
DATE & TIME
CityTime
CityTime is a quick and easy way to check the time in another city. Over 200 major cities of the world are supported.
UpTime
See how long your computer has been running, accurate to the second.
DateDiff
Calculate the number of days between two dates.