While in Windows Fundamentals 1 we covered the basic stuff such as Desktop, file system, UAC, control panel, etc, now it is time to go deeper: Let’s learn about System Configuration, how to modify UAC settings, what resource monitoring is, how the Windows registry works and more.
This is the second of the 3-part lesson from our #FromZeroToHacker Windows fundamentals.
Table of contents |
Introduction |
What I have learnt today? |
Stats |
Resources |
Introduction to Windows Fundamentals
We are going deeper into Windows: Time for learning about System Configuration and its tools
- Introduction to System Configuration
- How to manage UAC settings
- Computer management
- System information
- Resource monitor
- Command prompt
- Registry editor
What I have learnt today?
System configuration
Windows has a tool for advanced troubleshooting, MSConfig
, which helps us diagnose startup issues.
You can launch System Configuration from your Start Menu:
data:image/s3,"s3://crabby-images/bf58f/bf58f69f0d97ddd1e676804ccb5a9905c89d711d" alt="Windows fundamentals: System Configuration"
Once launched, we are presented with 5 tabs:
- General
- Boot
- Services
- Startup
- Tools
data:image/s3,"s3://crabby-images/53028/53028132f6821f3bb592ef82494d07ca02e9df2d" alt="Windows Fundamentals System configuration General Tab"
As we can see, in the General tab, we can select what devices and services are loaded when we boot our Windows.
data:image/s3,"s3://crabby-images/92152/92152293d09af3bed8025a98bf7376ce49762c62" alt="System configuration Boot Tab"
In the Boot tab, we can define various boot options.
data:image/s3,"s3://crabby-images/17797/177978b99b5d59dfd7b702263045ed8ed0921954" alt="System configuration Services Tab"
The Services tab lists all the services configured for the system (running or not). A service is a program that runs in the background.
data:image/s3,"s3://crabby-images/36422/364229ac2052ce62af88d1b3061e9c7971748cd9" alt="System configuration Services Tab"
The Startup tab doesn’t offer us too much: Just a link to open the Task Manager. This is because Task Manager lets us manage startup items.
data:image/s3,"s3://crabby-images/584c3/584c3a0a5dbc6a6a50978b82eeb31ca7df250ce7" alt="System configuration Tools Tab"
The Tools tab shows us a list of various utilities that let us configure the OS in a deeper way. Each tool has a brief description, providing with information about what the tool is for.
Let’s see some of them:
Change UAC controls
As we saw yesterday, UAC is a very important tool to prevent malware attacks in our Windows systems. We can change its settings by launching the UAC settings from the System Configuration, at the Tools tab.
data:image/s3,"s3://crabby-images/4a7ef/4a7ef7a6ccb4c634d8757e3a6c5f9ebf0268249d" alt="System Configuration Change UAC"
By simply moving the slider up and down, we change the UAC settings (You shouldn’t turn it off entirely). At the right side of the window, you can read what the current setting entails.
data:image/s3,"s3://crabby-images/0bb6d/0bb6d588621320bae0e7e3d9df6f7832f25cca99" alt="UAC control"
Computer management
Computer Management has three sections: System Tools, Storage and Services, and Applications.
data:image/s3,"s3://crabby-images/6767d/6767d62795fe0d626500150e7cfe071f3fb01952" alt="Windows Fundamentals Computer management"
System tools
data:image/s3,"s3://crabby-images/64623/646237b9cefec9670008ed26aa07ef7aaef31c72" alt="System tools"
Task Scheduler lets us manage common tasks that our computer will carry out automatically at the time specified. That task can be to just run an application, a script, etc. We can also specify to run a task periodically, for example, every 30 minutes.
data:image/s3,"s3://crabby-images/ab1e8/ab1e8f351c23c5682c6eef58719be4e92332e829" alt=""
Event Viewer allows us to view events that occurred on the computer. These logs can be read to understand the activity of the computer system. Normally we do this to diagnose errors we found on our Windows.
data:image/s3,"s3://crabby-images/1c52a/1c52ad971d08e9b02578ac78d249b4db76d3df79" alt="Event viewer general"
data:image/s3,"s3://crabby-images/4852c/4852c668a34a25d3044636043213b0ec188060b4" alt="Event viewer logs"
There are five types of events that can be logged in. More information on Microsoft Event Types:
data:image/s3,"s3://crabby-images/d4511/d4511480d5dcfb8e5ea0cf9c99c9413a87d2e561" alt="Windows Fundamentals Microsoft event types"
Shared folders is where you will see a list of shares and directories shared that others can connect to:
data:image/s3,"s3://crabby-images/0cb9a/0cb9a1b9e956e607ab1e5ee7c4b4ffcad6377ac0" alt="Computer management shared folders"
Under Shares you can find items shared with other users, under Sessions you will see a list of users currently connected to any shares, and finally, in Open files, there is a list of files and directories open by the connected users.
data:image/s3,"s3://crabby-images/bcb94/bcb94bfc822f297fa7f21121f62281d366932b87" alt="Local users and groups"
The Local users and groups bit is familiar to us, as we saw it yesterday on Windows Fundamentals: Part 1 – User groups
data:image/s3,"s3://crabby-images/1e72c/1e72ca6ac4f7c7eaf465747a1aa09dccddee21a5" alt="Performance monitor"
The Performance section let us view the performance data in real-time. We can create logs, configure and schedule performance counter, trace and configure data collection to analyze the results.
data:image/s3,"s3://crabby-images/a48ef/a48efbd3e1784ce62f32ea2cf2f78dc961efe03a" alt="Device manager"
The Device Manager allows us to view and configure the hardware our computer uses.
Storage
Under storage, there is Windows Server Backup and Disk Management. As we don’t have a server, we will only look at Disk Management.
data:image/s3,"s3://crabby-images/b3ee5/b3ee51732fccd4615b7c1b5b3ee3d8779ec9950d" alt="Storage"
Disk management let us perform advanced storage tasks such as setting up a new drive, extending or shrinking a partition, or changing drive letters.
Services and applications
data:image/s3,"s3://crabby-images/47096/4709622fe644c4e6ce9ee0d45e005abf73b43d7a" alt="Services and applications"
As we saw a few minutes ago, a service is a task that runs in the background. Here we can do more than just enable and disable a service. We, for example, can view the properties of a service:
data:image/s3,"s3://crabby-images/86671/866710f8c55b274996495be58e37633a1ac277e4" alt="Windows Fundamentals Service properties"
WMI Control configures and controls the Windows Management Instrumentation service or WMI.
WMI allows scripts to manage Windows personal computers and servers, locally and remotely.
System Information
Let’s keep talking about Tools from the System Configuration panel.
data:image/s3,"s3://crabby-images/cb983/cb98301c5c8f9650f8590aed40fdaaa2a943cab1" alt="Windows Fundamentals Service information"
This tool gathers information about your computer, displaying it in a comprehensive view of your hardware, software, and system components.
The System Summary displays general information from the computer:
data:image/s3,"s3://crabby-images/756ab/756ab141cfa6dd8f7020a1dcfa49a7618e2f6600" alt="System summary"
The information displayed in Hardware Resources is a bit more technical. If you want, you can learn more on the Official Microsoft page
data:image/s3,"s3://crabby-images/5ccc3/5ccc3fd44b1d488f07e6641bae82d17173dc3829" alt="Hardware resources"
Under Components, you will see specific information about hardware devices installed on your computer.
data:image/s3,"s3://crabby-images/21e64/21e64cd60729d03468ef4301073eee3d2eb65009" alt="Components"
In the Software Environment section, there is information about software from the core of your OS and the software you installed. Other details available are the Environment variables (Variables that store information about the OS environment such as the OS path, number of processors, etc) and Network connections.
data:image/s3,"s3://crabby-images/5f20e/5f20e264f9e4877996cb2ef5d14286734d7f43d9" alt="Software environment"
Resource Monitor
Resource monitor displays information about OS processes: Memory, Disk, and Network usage, along with details about which processes are using individual file handles and modules.
This utility is geared towards advanced users who need to perform advanced troubleshooting on the computer.
Besides Overview, this tool has four sections:
CPU
data:image/s3,"s3://crabby-images/df06d/df06d326b2e3fa9a60f6bb7106fdbe13151ef5a2" alt="Resource monitor CPU"
Memory
data:image/s3,"s3://crabby-images/6c1b1/6c1b132d263fc406db9084349d349c31b3f63f1b" alt="Resource monitor memory"
Disk
data:image/s3,"s3://crabby-images/0e54d/0e54d6a4553d55ed54e187084d092da1630020a7" alt="Resource monitor disk"
Network
data:image/s3,"s3://crabby-images/f55db/f55db38c8d91ab1d409fe5a257698baee33b21cb" alt="Resource monitor Network"
Command Prompt
The command prompt is the equivalent of the Linux Terminal. It also may seem daunting at first, but once you understand how to interact with it, it will become just another tool.
A few commands that we can use are whoami
, which outputs the name of the logged-in user, and hostname, which outputs the computer name.
A command used often to troubleshoot is ipconfig
, a command that shows the network addresses settings:
data:image/s3,"s3://crabby-images/b8b69/b8b692adf293634b116a863f730446ea75e765e8" alt="Windows Fundamentals terminal ipconfig"
A flag to retrieve the help manual, the equivalent of man
in Linux, is /?
:
data:image/s3,"s3://crabby-images/7776e/7776e17ee690e33ed59faf8230acc18c92ead2f2" alt="Windows Fundamentals terminal help"
You can find the most important commands in this freeCodeCamp link.
Registry editor
The Windows registry is a database where information necessary to configure the system is stored. Here, we can find data about:
- Profiles for each user
- Applications installed on the computer and the types of documents that each can create
- Property sheet settings for folders and application icons
- What hardware exists on the system
- The ports that are being used
This registry is for advanced computer users. Making any changes may affect normal computer operations. Believe me, I did (and not in a good way :/).
data:image/s3,"s3://crabby-images/333c1/333c1ea1807649e9d255ce124de4f281c7480ca6" alt="Windows Fundamentals Registry Editor"
Stats
From 203.950th to 195.022th. Finally reaching the top 10%!
Here is also the Skill Matrix:
data:image/s3,"s3://crabby-images/1ebee/1ebeec1143c2ff1530d9645682b5892b3271ef94" alt="Windows Fundamentals Skill matrix"
Resources
Path: Pre Security
Windows Fundamentals
TryHackMe: Windows fundamentals part 2
Other resources
Microsoft Event Types
Hardware Resources: Official Microsoft page
Command Line Commands