Windows Sysinternals Suite (Build January 4, 2016)

Microsoft has released an update version (January 4, 2016) of Windows Sysinternals Suite. This new release contains an updated version of Sigcheck v2.4, Sysmon v3.2, Process Explorer v16.1, Autoruns v13.51 and AccessChk v6.01.

Download Windows Sysinternals Suite
Windows Sysinternals Suite is available for download from following website:

Overview
The Windows Sysinternals troubleshooting utilities have been rolled up into a single suite of tools. These utilities can help you to manage, troubleshoot and diagnose your Windows systems and applications. Each file contains the individual troubleshooting tools and help files.

Note: Windows Sysinternals does not contain non-troubleshooting tools like the BSOD Screen Saver or NotMyFault.

What's new in this version?
Windows Sysinternals Suite (January 4, 2016) contains following updates:

Sigcheck v2.4
This update to Sigcheck, a powerful command-line utility that reports image file and signing information, as well as information on certificates, now has an option that will report any certificates installed on the system that do not chain to one of the certificates in the Microsoft certificate trust list (CTL). It also adds the ability to take image information captured from Sigcheck on a system disconnected from the Internet and obtain VirusTotal status from one that’s connected.

Sysmon v3.2
This release of Sysmon, a background service that logs security-relevant process and network activity to the Windows event log, now has the option of logging raw disk and volume accesses, operations commonly performed by malicious toolkits to read information by bypassing higher-level security features. Thanks to David Magnotti for the contribution.

Process Explorer v16.1
Process Explorer now includes a column in the handle view that reports the text version of handle access masks, as well as several bug fixes including one that would result in the suspension of .NET threads when viewed via the stack dialog.

Autoruns v13.51
This release of Autoruns, a comprehensive autostart entry manager, fixes a WMI command-line parsing bug, emits a UNICODE BOM in the file generated when saving results to a text file, and adds back the ability to selectively verify the signing status of individual entries.

AccessChk v6.01
This release of AccessChk, a command-line utility that reports effective and actual access for many different object types including files, registry keys, and services, now handles accounts with long names, fixes a bug that prevented reporting of kernel object accesses when run elevated, and fixes the inadvertent creation of a registry key when querying a non-existent key.

Sysinternals Live:
Sysinternals Live is a service that enables you to execute Sysinternals tools directly from the Web without hunting for and manually downloading them. Simply enter a tool's Sysinternals Live path into Windows Explorer or a command prompt as http://live.sysinternals.com/[toolname] or \\live.sysinternals.com\tools\[toolname].

You can view the entire Sysinternals Live tools directory in a browser at http://live.sysinternals.com.

Reference:
Windows Sysinternals

No comments: