Get an edge on Windows diagnostics and support—direct from the Sysinternals experts at Microsoft. The Windows Sysinternals tools, available for download from Microsoft TechNet, are designed to help you manage, troubleshoot, and diagnose Windows clients and servers. This Administrator’s Reference provides essential, scenario-based guidance and inside insights to help maximize your work with these tools.Get timesaving solutions, workarounds, and troubleshooting tips from Windows internals expert Marc Russinovich and senior MCS consultant Aaron Margosis Drill into the features and functions of Sysinternals utilities and references, gleaning practical, hands-on insights for resolving real-world issues Learn to work more effectively with utilities for managing, troubleshooting, and optimizing files, disks, processes, security features, networking, maintenance, and other essential operations Marc Russinovich is a Technical Fellow on the Windows Azure team at Microsoft. He is coauthor of the classic Windows Internals book and cofounder of the Sysinternals website. He is a contributing editor for Microsoft TechNet and Windows IT Pro magazine, and speaks at several industry events.Aaron Margosis is a senior consultant with Microsoft Consulting Services (MCS), the author of the popular MakeMeAdmin and PrivBar tools, and a passionate evangelist for the use of “least privilege” on Windows.
Mark Russinovich is a Technical Fellow in Windows Azure, Microsoft's cloud operating system group. Russinovich is a widely recognized expert in Windows operating system internals as well as operating system architecture and design.
Russinovich joined Microsoft when Microsoft acquired Winternals software, the company he cofounded in 1996 and where he worked as Chief Software Architect. He is also cofounder of Sysinternals.com, where he wrote and published dozens of popular Windows administration and diagnostic utilities including Autoruns, Process Explorer and Tcpview.
Russinovich coauthored "Windows Internals" and "The Sysinternals Administrator's Reference," both from Microsoft Press, authored the cyberthriller Zero Day, is a Contributing Editor for TechNet Magazine and Senior Contributing Editor for Windows IT Pro Magazine, and has written many articles on Windows internals. He has been a featured speaker at major industry conferences around the world, including Microsoft's TechEd, IT Forum, and Professional Developer's Conference, as well as Windows Connections, Windev, and TechMentor, and has taught Windows internals, troubleshooting and file system and device driver development to companies worldwide, including Microsoft, the CIA and the FBI. Russinovich earned his Ph.D. in computer engineering from Carnegie Mellon University.
Too much time covering command line flags and menu items, not enough time covering case studies of how to use the tools. The final section that does this is really good, but unfortunately rather short compared to the reference portion.
This book focuses on explaining how to use Sysinternals tools (options available, command line parameters, etc). It's not technically hard to understand for a Windows admin. It's good for a begginer and intermediate, but not enough for a pro. Final chapters are the best ones because deepens into real case scenarios. Unfortunatelly, that section is extremely short. I would appreciate more examples like these.
This is a great companion if you’ve got use cases for SysInternals that really require leveraging all the advanced features and everything SysInternals has to offer. If you just want to learn how these tools work, you can get by with searching for blog posts or simply experimenting with them on a test system. So it can be hard to really get a good return on your time and money reading this book cover to cover. I found it much more valuable when I had specific projects that required, for example, diving deep into Autoruns.exe. In which case it was an excellent resource that covers things I was not able to find anywhere on the internet.