Uploaded October 2025 | Updated September 2026, 1 week ago
tcm.rocks/soc201-y - These concepts are addressed in our SOC 201 course, which you can find in the TCM Security Academy.
Performing live examination on an endpoint means that you are investigating a system while it is actively running. And at some point, during an active intrusion, malware also needs to run as a process (or at least hide in an active process.)
This makes performing analysis an important early step during live investigations. And in this video, Andrew Prince focuses on the different ways to interrogate processes on a Windows endpoint.
Watch last month's PowerShell introduction video here: youtube.com/watch?v=GyvEMcMh3rc
If you want to challenge yourself to go even further with these sorts of concepts, consider taking our PSAP (Practical SOC Analyst Professional) exam. Sign up here: tcm.rocks/psap-y
#powershell #cybersecurity #blueteam #malware #threathunting
Sponsor a Video: tcm.rocks/Sponsors
Pentests & Security Consulting: tcm-sec.com
Get Trained: academy.tcm-sec.com
Get Certified: certifications.tcm-sec.com
Merch: merch.tcm-sec.com
📱Social Media📱
___________________________________________
X: https://x.com/TCMSecurity
Twitch: twitch.tv/thecybermentor
Instagram: instagram.com/tcmsecurity
LinkedIn: linkedin.com/company/tcm-security-inc
TikTok: tiktok.com/@tcmsecurity
Discord: discord.gg/tcm
Facebook: facebook.com/tcmsecure
Timestamps:
0:00 - Introduction
1:14 - What are Processes?
2:20 - Legacy Process Enumeration
5:58 - Get-Process
7:52 - The Filter Left Principle
9:55 - Filtering with the Pipeline
13:30 - Get-CimInstance
17:45 - Decoding Command Lines
20:28 - Conclusion
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: amzn.to/31GN7iX
The Hacker Playbook 3: amzn.to/34XkIY2
Hacking: The Art of Exploitation: amzn.to/2VchDyL
The Web Application Hacker's Handbook: amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: amzn.to/2V9srOe
Linux Basics for Hackers: amzn.to/34WvcXP
Python Crash Course, 2nd Edition: amzn.to/30gINu0
Violent Python: amzn.to/2QoGoJn
Black Hat Python: amzn.to/2V9GpQk
My Build:
lg 32gk850g-b 32" Gaming Monitor:amzn.to/30C0qzV
darkFlash Phantom Black ATX Mid-Tower Case: amzn.to/30d1UW1
EVGA 2080TI: amzn.to/30d2lj7
MSI Z390 MotherBoard: amzn.to/30eu5TL
Intel 9700K: amzn.to/2M7hM2p
G.SKILL 32GB DDR4 RAM: amzn.to/2M638Zb
Razer Nommo Chroma Speakers: amzn.to/30bWjiK
Razer BlackWidow Chroma Keyboard: amzn.to/2V7A0or
CORSAIR Pro RBG Gaming Mouse: amzn.to/30hvg4P
Sennheiser RS 175 RF Wireless Headphones: amzn.to/31MOgpu
My Recording Equipment:
Panasonic G85 4K Camera: amzn.to/2Mk9vsf
Logitech C922x Pro Webcam: amzn.to/2LIRxAp
Aston Origin Microphone: amzn.to/2LFtNNE
Rode VideoMicro: amzn.to/309yLKH
Mackie PROFX8V2 Mixer: amzn.to/31HKOMB
Elgato Cam Link 4K: amzn.to/2QlicYx
Elgato Stream Deck: amzn.to/2OlchA5
*We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.
tcm.rocks/soc201-y - These concepts are addressed in our SOC 201 course, which you can find in the TCM Security Academy.
Performing live examination on an endpoint means that you are investigating a system while it is actively running. And at some point, during an active intrusion, malware also needs to run as a process (or at least hide in an active process.)
This makes performing analysis an important early step during live investigations. And in this video, Andrew Prince focuses on the different ways to interrogate processes on a Windows endpoint.
Watch last month's PowerShell introduction video here: youtube.com/watch?v=GyvEMcMh3rc
If you want to challenge yourself to go even further with these sorts of concepts, consider taking our PSAP (Practical SOC Analyst Professional) exam. Sign up here: tcm.rocks/psap-y
#powershell #cybersecurity #blueteam #malware #threathunting
Sponsor a Video: tcm.rocks/Sponsors
Pentests & Security Consulting: tcm-sec.com
Get Trained: academy.tcm-sec.com
Get Certified: certifications.tcm-sec.com
Merch: merch.tcm-sec.com
📱Social Media📱
___________________________________________
X: https://x.com/TCMSecurity
Twitch: twitch.tv/thecybermentor
Instagram: instagram.com/tcmsecurity
LinkedIn: linkedin.com/company/tcm-security-inc
TikTok: tiktok.com/@tcmsecurity
Discord: discord.gg/tcm
Facebook: facebook.com/tcmsecure
Timestamps:
0:00 - Introduction
1:14 - What are Processes?
2:20 - Legacy Process Enumeration
5:58 - Get-Process
7:52 - The Filter Left Principle
9:55 - Filtering with the Pipeline
13:30 - Get-CimInstance
17:45 - Decoding Command Lines
20:28 - Conclusion
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: amzn.to/31GN7iX
The Hacker Playbook 3: amzn.to/34XkIY2
Hacking: The Art of Exploitation: amzn.to/2VchDyL
The Web Application Hacker's Handbook: amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: amzn.to/2V9srOe
Linux Basics for Hackers: amzn.to/34WvcXP
Python Crash Course, 2nd Edition: amzn.to/30gINu0
Violent Python: amzn.to/2QoGoJn
Black Hat Python: amzn.to/2V9GpQk
My Build:
lg 32gk850g-b 32" Gaming Monitor:amzn.to/30C0qzV
darkFlash Phantom Black ATX Mid-Tower Case: amzn.to/30d1UW1
EVGA 2080TI: amzn.to/30d2lj7
MSI Z390 MotherBoard: amzn.to/30eu5TL
Intel 9700K: amzn.to/2M7hM2p
G.SKILL 32GB DDR4 RAM: amzn.to/2M638Zb
Razer Nommo Chroma Speakers: amzn.to/30bWjiK
Razer BlackWidow Chroma Keyboard: amzn.to/2V7A0or
CORSAIR Pro RBG Gaming Mouse: amzn.to/30hvg4P
Sennheiser RS 175 RF Wireless Headphones: amzn.to/31MOgpu
My Recording Equipment:
Panasonic G85 4K Camera: amzn.to/2Mk9vsf
Logitech C922x Pro Webcam: amzn.to/2LIRxAp
Aston Origin Microphone: amzn.to/2LFtNNE
Rode VideoMicro: amzn.to/309yLKH
Mackie PROFX8V2 Mixer: amzn.to/31HKOMB
Elgato Cam Link 4K: amzn.to/2QlicYx
Elgato Stream Deck: amzn.to/2OlchA5
*We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.










