HandleFile
Identifies files of running processes using handles they've got opened.
Usage
HandleFile:<handletype>,<handlename>[,advanced file parameters]
Examples
HandleFile:"file","\Test\HelloWorld.txt"
Identifies the process that currently has an open file handle to, for example, C:\Test\HelloWorld.txt.
Description
- This can be either a valid handle type name, or anything else to scan for all handle types. The handle type names supported here are, case-insensitive (please keep them lowercase anyway):
- mutex
- file
- semaphor
- Specify the name of the handle as second parameter. AP
- Advanced file parameters may further limit down the list of matches to avoid ambiguous names. One special parameter here is rescan, which set to 1 will re-read the list of handles.
This command is available only as a plugin update currently; your updates should be at at least 2008-02-27 (beta update users) or 2008-03-05 (public update users).
Scan Results
- Identified files.