> For the complete documentation index, see [llms.txt](https://pellaeon.gitbook.io/mobile-forensics/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pellaeon.gitbook.io/mobile-forensics/windows.md).

# Checking Windows Computers

*Note: This section is also available in* [*French*](https://pellaeon.gitbook.io/mobile-forensics/fr/windows)*,* [*Spanish*](https://pellaeon.gitbook.io/mobile-forensics/es/windows)*,* [*Brazilian Portuguese*](https://pellaeon.gitbook.io/mobile-forensics/pt-br/windows)*, and* [*Arabic*](https://pellaeon.gitbook.io/mobile-forensics/ar/windows)*.*

In this section we will go through some of the basic steps to take when checking a suspected Windows computer. Following are the tools (with links to their respective download pages) we are going to demonstrate here:

* [Sysinternals Autoruns](https://technet.microsoft.com/en-ca/sysinternals/bb963902.aspx) produced by Microsoft.
* [Sysinternals Process Explorer](https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer) produced by Microsoft.
* [CrowdInspect](https://www.crowdstrike.com/resources/community-tools/crowdinspect-tool/) produced by CrowdStrike.
* [Sysinternals TCPView](https://technet.microsoft.com/en-us/sysinternals/tcpview.aspx) produced by Microsoft.
* [pcqf](https://github.com/botherder/pcqf) (originally SnoopDigg) produced by Claudio Guarnieri. (Last updated in 2021.)
