Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Summary

Summary Windows Processes: Key Notes and Quick Reference

Rating
-
Sold
-
Pages
5
Uploaded on
12-02-2025
Written in
2024/2025

For you to catch the abnormal, you need to understand what’s normal. This document provides a concise yet comprehensive summary of key Windows processes—their purpose, typical file paths, parent processes, expected number of instances and more. It’s an essential quick reference for IT professionals, SOC analysts, and threat hunters to recognize legitimate processes, detect anomalies, and strengthen threat detection capabilities. Perfect for sharpening your process monitoring and security investigation skills.

Show more Read less
Institution
Course

Content preview

Windows Processes
Writer Khadijah Alamoudi

Email

LinkedIn https://www.linkedin.com/in/khadijah-alamoudi-6aa1211bb




All in One Summarized Table

Processes Purpose Executable Path Parent # of Instance Username

Session Manager, create new
sessions.
NT
• Session 0 starts csrss.exe and
smss.exe %SystemRoot%\System32\smss.exe System 1 AUTHORIT
wininit.exe. (OS services)
(S-1-5-18)
• Session 1 starts csrss.exe and
winlogon.exe. (User session)

Client/Server Run Subsystem Created by
Process; manages processes and child instance
threads, provides Windows API, of SMSS.EXE
NT
maps drive letters, creates temp but
csrss.exe %SystemRoot%\System32\csrss.exe 2 AUTHORIT
files, handles shutdown. • will be that process
(S-1-5-18)
available per newly created user will exist so will
session. appear as no
parent

Created by a
child instance
Windows Logon Process; handles
of SMSS.EXE ,
user logons/logoffs, launches NT
winlogon.exe but
LogonUI.exe for login, and passes %SystemRoot%\System32\winlogon.exe AUTHORIT
winlogon.exe
credentials to LSASS.exe for (S-1-5-18)
will appear as if
verification.
it has no parent
process.

Created by
child instance
of SMSS.EXE
Windows Initialization Process;
but NT
wininit.exe responsible for launching
%SystemRoot%\System32\wininit.exe that process 1 AUTHORIT
services.exe , lsass.exe , and
will exist so will (S-1-5-18)
lsm.exe in Session 0.
appear as no
parent


Local Session Manager; works
with smss.exe to create, destroy,
NT
lsm.exe or manage user sessions.
%SystemRoot%\System32\lsm.exe wininit.exe 1 AUTHORIT
Manages logon/off, shell
(S-1-5-18)
start/end, and desktop
lock/unlock.

Service Control Manager; loads
services and device drivers into
memory, and manages service
NT
services.exe operations. ~ responsible for %SystemRoot%\System32\services.exe
wininit.exe 1 AUTHORIT
handling system services
(S-1-5-18)
including starting and ending
services, and interacting with
services.

Local Security Authority
Subsystem; handles user NT
lsass.exe
authentication, generates access %SystemRoot%\System32\lsass.exe wininit.exe 1 AUTHORIT
tokens, and enforces security (S-1-5-18)

Written for

Course

Document information

Uploaded on
February 12, 2025
Number of pages
5
Written in
2024/2025
Type
SUMMARY

Subjects

$4.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller
Seller avatar
cyberiau007

Get to know the seller

Seller avatar
cyberiau007 Imam Abdulrahman Bin Faisal University
Follow You need to be logged in order to follow users or courses
Sold
-
Member since
1 year
Number of followers
0
Documents
1
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions