{"id":2725,"date":"2026-04-03T18:47:00","date_gmt":"2026-04-03T18:47:00","guid":{"rendered":"https:\/\/zombierollz.blog\/?p=2725"},"modified":"2026-04-03T12:47:28","modified_gmt":"2026-04-03T12:47:28","slug":"core-windows-proccesses","status":"publish","type":"post","link":"https:\/\/zombierollz.blog\/?p=2725","title":{"rendered":"Core Windows Proccesses"},"content":{"rendered":"\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-c661f4dbc6bc0d5128fc966fed5db815\"><a href=\"https:\/\/tryhackme.com\/room\/btwindowsinternals\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/btwindowsinternals<\/a><br>Created by: tryhackme, ar33zy<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-c1e37ae616b721c662713d41612cfa0a\">This room is a pre-requisite for <a href=\"https:\/\/tryhackme.com\/room\/volatility\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/volatility<\/a> and that room is a pre-requisite for <a href=\"https:\/\/tryhackme.com\/room\/boogeyman2\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/boogeyman2<\/a> which is a part of the SOCL1 pathway.<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-6e34374333eb971d5db674b45ff57ffd\">&#8220;In this room, we will explore the core processes within a Windows system. This room aims to help you know and understand what normal behaviour within a Windows operating system is. This foundational knowledge will&nbsp;<strong>help<\/strong>&nbsp;you identify malicious processes running on an endpoint.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"420\" height=\"681\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-061929.png\" alt=\"\" class=\"wp-image-2727\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-061929.png 420w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-061929-185x300.png 185w\" sizes=\"auto, (max-width: 420px) 100vw, 420px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-3ab33750011dc089f36d54ad4d58a845\">I am already familiar with the majority of the content, but it&#8217;s been a while, and I am looking forward to a refresher. Task 2 covers the handy Task Manager.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"723\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063821-1024x723.png\" alt=\"\" class=\"wp-image-2728\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063821-1024x723.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063821-300x212.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063821-768x542.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063821.png 1161w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-8a8cf25f8dcaf0790a109c5da8b88805\">They bring up two additional utilities: Process Hacker and Process Explorer. I&#8217;ve used the latter in other THM rooms.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"663\" height=\"594\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063944.png\" alt=\"\" class=\"wp-image-2729\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063944.png 663w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-063944-300x269.png 300w\" sizes=\"auto, (max-width: 663px) 100vw, 663px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-d3c5acf961bf5297b29f26bd45615fa1\">Takes 3 covers the System process and what is to be expected when you look at it&#8217;s properties.<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-038fa6b0abf4ac7243d6c376323b5e06\">&#8220;The first Windows process on the list is\u00a0<strong>System<\/strong>. It was mentioned in a previous section that a\u00a0PID\u00a0for any given process is assigned at random, but that is not the case for the System process. The\u00a0PID\u00a0for System is always 4. What does this process do exactly?<br><br>The official definition from Windows Internals 6th Edition:<br><br>&#8216;<em>The System process (process ID 4) is the home for a special kind of thread that runs only in kernel mode a kernel-mode system thread. System threads have all the attributes and contexts of regular user-mode threads (such as a hardware context, priority, and so on) but are different in that they run only in kernel-mode executing code loaded in system space, whether that is in Ntoskrnl.exe or in any other loaded device driver. In addition, system threads don&#8217;t have a user process address space and hence must allocate any dynamic storage from operating system memory heaps, such as a paged or nonpaged pool.<\/em>&#8216;&#8221;<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-a82ff0afe0c378d8d3c4864586333958\">&#8220;What is user mode? Kernel-mode? Visit the following\u00a0<a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/gettingstarted\/user-mode-and-kernel-mode\" target=\"_blank\" rel=\"noreferrer noopener\">link(opens in new tab)<\/a>\u00a0to understand each of these.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"709\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070006-1024x709.png\" alt=\"\" class=\"wp-image-2730\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070006-1024x709.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070006-300x208.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070006-768x531.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070006.png 1175w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-0efb65d1f35970353ebf4aab3d45dfec\">I decided to open Process Hacker and look at the differences. With Process Hacker, we get more details!<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"609\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070247-1024x609.png\" alt=\"\" class=\"wp-image-2731\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070247-1024x609.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070247-300x179.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070247-768x457.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-070247.png 1166w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"641\" height=\"167\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071530.png\" alt=\"\" class=\"wp-image-2732\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071530.png 641w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071530-300x78.png 300w\" sizes=\"auto, (max-width: 641px) 100vw, 641px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-1e38728786e4fd0bd880a2a5692c32f2\">&#8220;What PID should System always be?&#8221;<br><br>4<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-23e375c7b010eb8aba1b5d325dd4d937\">Task 4 covers smss.exe.<br><br>&#8220;The next process is\u00a0<strong>smss.exe<\/strong>\u00a0(<strong>Session Manager Subsystem<\/strong>). This process, also known as the\u00a0<strong>Windows Session Manager<\/strong>, is responsible for creating new sessions. It is the first user-mode process started by the kernel.<br><br>This process starts the kernel and user modes of the Windows subsystem (you can read more about the NT Architecture\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Architecture_of_Windows_NT\" target=\"_blank\" rel=\"noreferrer noopener\">here(opens in new tab)<\/a>). This subsystem includes win32k.sys (kernel mode), winsrv.dll\u00a0(user mode), and csrss.exe (user mode).\u00a0<br><br>Smss.exe starts csrss.exe (Windows subsystem) and wininit.exe in Session 0, an isolated Windows session for the operating system, and csrss.exe and winlogon.exe for Session 1, which is the user session. The first child instance creates child instances in new sessions, done by smss.exe copying itself into the new session and self-terminating.\u00a0You can read more about this process\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Session_Manager_Subsystem\" target=\"_blank\" rel=\"noreferrer noopener\">here(opens in new tab)<\/a>.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"584\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071436-1024x584.png\" alt=\"\" class=\"wp-image-2733\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071436-1024x584.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071436-300x171.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071436-768x438.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071436.png 1174w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"641\" height=\"167\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071530-1.png\" alt=\"\" class=\"wp-image-2734\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071530-1.png 641w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-071530-1-300x78.png 300w\" sizes=\"auto, (max-width: 641px) 100vw, 641px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-eb17bfe5efc1bce422a2fc6940439b6a\">&#8220;Aside from csrss.exe, what process does smss.exe spawn in Session 1?&#8221;<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-a487d5514178d7abfba2c1cfd8a75e73\">winlogon.exe<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-e625b25f9c5f9023877f5915ea941a38\">On to task 5, csrss.exe.<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-ed69824d7c1dd188bdc1ac05c667a6ee\">&#8220;As mentioned in the previous section,\u00a0<strong>csrss.exe<\/strong>\u00a0(<strong>Client Server Runtime Process<\/strong>) is the user-mode side of the Windows subsystem. This process is always running and is critical to system operation. If this process is terminated by chance, it will result in system failure. This process is responsible for creating and deleting Win32 console windows and process threads. For each instance, csrsrv.dll, basesrv.dll, and winsrv.dll\u00a0are loaded (along with others).\u00a0<br><br>This process is also responsible for making the Windows\u00a0API\u00a0available to other processes, mapping drive letters, and handling the Windows shutdown process.\u00a0You can read more about this process\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Client\/Server_Runtime_Subsystem\" target=\"_blank\" rel=\"noreferrer noopener\">here(opens in new tab)<\/a>.<br><br><strong>Note<\/strong>: Recall that csrss.exe and winlogon.exe are called from smss.exe at startup for Session 1.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083227-1024x768.png\" alt=\"\" class=\"wp-image-2735\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083227-1024x768.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083227-300x225.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083227-768x576.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083227.png 1029w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"651\" height=\"310\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-082434.png\" alt=\"\" class=\"wp-image-2736\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-082434.png 651w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-082434-300x143.png 300w\" sizes=\"auto, (max-width: 651px) 100vw, 651px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-020589d94348a131ae815ea441f11543\">&#8220;What was the process that had PID 384 and PID 488?&#8221;<br>smss.exe<br><br>On to task 6, wininit.exe.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"649\" height=\"249\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083520.png\" alt=\"\" class=\"wp-image-2737\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083520.png 649w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-083520-300x115.png 300w\" sizes=\"auto, (max-width: 649px) 100vw, 649px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"727\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093824.png\" alt=\"\" class=\"wp-image-2738\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093824.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093824-300x284.png 300w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"435\" height=\"285\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093905.png\" alt=\"\" class=\"wp-image-2739\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093905.png 435w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093905-300x197.png 300w\" sizes=\"auto, (max-width: 435px) 100vw, 435px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-497293028e70a7177cebab8b7fcc86aa\">&#8220;Which process might you not see running if Credential Guard is not enabled?&#8221;<br><br>lsaiso.exe<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-ff614fcccb685f3b7756cc9e35c6a785\">Up next is task 7, winini.texe &gt; services.exe.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"646\" height=\"340\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-085743.png\" alt=\"\" class=\"wp-image-2740\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-085743.png 646w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-085743-300x158.png 300w\" sizes=\"auto, (max-width: 646px) 100vw, 646px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"727\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093824-1.png\" alt=\"\" class=\"wp-image-2741\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093824-1.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093824-1-300x284.png 300w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"435\" height=\"285\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093905-1.png\" alt=\"\" class=\"wp-image-2743\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093905-1.png 435w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-093905-1-300x197.png 300w\" sizes=\"auto, (max-width: 435px) 100vw, 435px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-a2ffda6d579364ca4ca9c86fb7858909\">&#8220;How many instances of services.exe should be running on a Windows system?&#8221;<br>1<br><br>On to Task 8, wininit.exe > services.exe > svchost.exe<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"644\" height=\"203\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-115959.png\" alt=\"\" class=\"wp-image-2742\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-115959.png 644w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-02-115959-300x95.png 300w\" sizes=\"auto, (max-width: 644px) 100vw, 644px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1005\" height=\"831\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053543.png\" alt=\"\" class=\"wp-image-2744\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053543.png 1005w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053543-300x248.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053543-768x635.png 768w\" sizes=\"auto, (max-width: 1005px) 100vw, 1005px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"821\" height=\"828\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053720.png\" alt=\"\" class=\"wp-image-2745\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053720.png 821w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053720-297x300.png 297w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053720-150x150.png 150w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-053720-768x775.png 768w\" sizes=\"auto, (max-width: 821px) 100vw, 821px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"622\" height=\"762\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-054755.png\" alt=\"\" class=\"wp-image-2746\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-054755.png 622w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-054755-245x300.png 245w\" sizes=\"auto, (max-width: 622px) 100vw, 622px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-f8ee1518e8ff6a252ccbd20dd48ce1a6\">&#8220;What single letter parameter should always be visible in the\u00a0<strong>Command line<\/strong>\u00a0or\u00a0<strong>Binary path<\/strong>?&#8221;<br><br>k<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-3c29a96ad03fcde7444022a170d45356\">On to task 9, lass.exe.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"638\" height=\"178\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-055132.png\" alt=\"\" class=\"wp-image-2747\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-055132.png 638w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-055132-300x84.png 300w\" sizes=\"auto, (max-width: 638px) 100vw, 638px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-97354d4f89fd03c15bb8c7d334813975\">A great article of how that expands on lsass as well as how it can used abused and what to do to defend it:<br><a href=\"https:\/\/yungchou.wordpress.com\/2016\/03\/14\/an-introduction-of-windows-10-credential-guard\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/yungchou.wordpress.com\/2016\/03\/14\/an-introduction-of-windows-10-credential-guard\/<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"653\" height=\"686\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-061041.png\" alt=\"\" class=\"wp-image-2750\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-061041.png 653w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-061041-286x300.png 286w\" sizes=\"auto, (max-width: 653px) 100vw, 653px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-7e0385527361317438737d2b77342c25\">&#8220;What is the parent process for LSASS?&#8221;<br>wininit.exe<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-30dc70de4cc7ee0f9751b1f450a5804b\">On to task 10, winlogon.exe.<br><br>&#8220;The\u00a0<strong>Windows Logon<\/strong>,\u00a0<strong>winlogon.exe<\/strong>, is responsible for handling the\u00a0<strong>Secure Attention Sequence<\/strong>\u00a0(SAS). It is the ALT+CTRL+DELETE key combination users press to enter their username &amp; password.\u00a0<br><br>This process is also responsible for loading the user profile. It loads the user&#8217;s NTUSER.DAT into HKCU, and userinit.exe loads the user&#8217;s shell. Read more about this process\u00a0<a href=\"https:\/\/docs.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-2000-server\/cc939862(v=technet.10)?redirectedfrom=MSDN\" target=\"_blank\" rel=\"noreferrer noopener\">here(opens in new tab)<\/a>.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"539\" height=\"621\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-063743.png\" alt=\"\" class=\"wp-image-2749\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-063743.png 539w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-063743-260x300.png 260w\" sizes=\"auto, (max-width: 539px) 100vw, 539px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"646\" height=\"348\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-063845.png\" alt=\"\" class=\"wp-image-2751\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-063845.png 646w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-063845-300x162.png 300w\" sizes=\"auto, (max-width: 646px) 100vw, 646px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-67acd59785b1abde7c8261403523a36c\">&#8220;What is the non-existent parent process for winlogon.exe?&#8221;<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-6a16ba852fbdf1edcb0cd28505adbf08\">smss.exe<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-50e4d095e3cec0cacea88b2dafd08a06\">On to the last task, task 11.<br><br>&#8220;The last process we&#8217;ll look at is\u00a0<strong>Windows Explorer<\/strong>,\u00a0<strong>explorer.exe<\/strong>. This process gives the user access to their folders and files. It also provides functionality for other features, such as the Start Menu and Taskbar.<br><br>As mentioned previously, the Winlogon process runs userinit.exe, which launches the value in\u00a0<code>HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell<\/code>.\u00a0Userinit.exe exits after spawning explorer.exe. Because of this, the parent process is non-existent.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"531\" height=\"602\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-064211.png\" alt=\"\" class=\"wp-image-2752\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-064211.png 531w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-064211-265x300.png 265w\" sizes=\"auto, (max-width: 531px) 100vw, 531px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"661\" height=\"384\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-064308.png\" alt=\"\" class=\"wp-image-2753\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-064308.png 661w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-064308-300x174.png 300w\" sizes=\"auto, (max-width: 661px) 100vw, 661px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-75e2fa304995ec719986d9cacf726e35\">&#8220;What is the non-existent process for explorer.exe?&#8221;<br><br>userinit.exe<\/p>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/tryhackme.com\/room\/btwindowsinternalsCreated by: tryhackme, ar33zy This room is a pre-requisite for https:\/\/tryhackme.com\/room\/volatility and that room is a pre-requisite for https:\/\/tryhackme.com\/room\/boogeyman2 which is a part of the SOCL1 pathway. &#8220;In this room, we will explore the core processes within a Windows system. This room aims to help you know and understand what normal behaviour within a Windows [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2725","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2725","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2725"}],"version-history":[{"count":2,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2725\/revisions"}],"predecessor-version":[{"id":2754,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2725\/revisions\/2754"}],"wp:attachment":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2725"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}