Applications & Services

The applications and services of a Windows system can be listed through the command prompt. Some of the characteristics of the progams can also be modified through the command prompt.

chevron-rightOS Architecturehashtag
wmic OS get OSArchitecture
chevron-rightList Applications and their propertieshashtag
#Command Prompt
Wmic product get name, version, vendor
wmic qfe get Caption, Description, HotFixID, InstalledOn
#Powershell
#32 Bit
Get-ItemProperty "HKLM:\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*" | select displayname
#64 Bit
Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*" | select displayname
chevron-rightList Running Applicationshashtag
Get-Process
#Powershell - Can be run using RDP only
Get-CimInstance -ClassName win32_service | Select Name,State,PathName | Where-Object {$_.State -like 'Running'}
chevron-rightList Installed Drivershashtag
Driveryquery /v
chevron-rightList loaded Drivershashtag

https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/driverqueryarrow-up-right

driverquery.exe /v /fo csv | ConvertFrom-CSV | Select-Object ‘Display Name’, ‘Start Mode’, Path
chevron-rightList versions of Drivershashtag
chevron-rightList Scheduled Taskshashtag
chevron-rightProcmon.exe - Filesystem, Registry and Process/thread activityhashtag
chevron-rightIcacls.exe - Lists/Modifies Discretionary ACLs of fileshashtag
chevron-rightCheck Startup Type of Appshashtag
chevron-rightList Firewall Ruleshashtag
chevron-rightEnable RDP through Registry Entry hashtag

This is a very important command as this can be used to enable RDP on a system once you have privileged access to a terminal,

chevron-rightList Serviceshashtag

The following command can be used to list the services installed on the computer,

chevron-rightStart/Stop a Servicehashtag

The windows SC command can be used to start or stop a service that is installed,

chevron-rightRestart Servicehashtag

The following command can be used to restart a windows service through Powershell,

Last updated