排查监听进程及父进程命令记录


netstat -ano |findstr ESTABLISHED

image

 

wmic process where processid=XXXX get parentprocessid,name,executablepath,commandline

image

 



posted @ 2025-12-26 08:44  Cong0ks  阅读(3)  评论(0)    收藏  举报