Skip to content

Instantly share code, notes, and snippets.

@steviecoaster
Created July 28, 2022 19:31
Show Gist options
  • Save steviecoaster/5926d335d8008bfd4d9ab7b5ca454a92 to your computer and use it in GitHub Desktop.
Save steviecoaster/5926d335d8008bfd4d9ab7b5ca454a92 to your computer and use it in GitHub Desktop.
SysInternals Enhanced Crescendo Schema
{
"Commands": [
{
"Verb": "Show",
"Noun": "ClockResolution",
"OriginalName": "clockres.exe",
"OriginalCommandElements": [
"-nobanner",
"-accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Show",
"Noun": "CoreInfo",
"OriginalName": "coreinfo.exe",
"OriginalCommandElements": [
"-nobanner",
"-accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "Cores",
"OriginalName": "-c",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "Features",
"OriginalName": "-f",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "Groups",
"OriginalName": "-g",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "Caches",
"OriginalName": "-l",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "NumaNodes",
"OriginalName": "-n",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "Sockets",
"OriginalName": "-s",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "NumaAccessCost",
"OriginalName": "-m",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "Virtualization",
"OriginalName": "-v",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Find",
"Noun": "Links",
"OriginalName": "FindLinks.exe",
"OriginalCommandElements": [
"-nobanner",
"accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "File",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 2147483647,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Find",
"Noun": "Handle",
"OriginalName": "handle.exe",
"OriginalCommandElements": [
"-nobanner"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "Name",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 2147483647,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "Process",
"OriginalName": "-p",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "Switch",
"Position": 2147483647,
"Name": "UserName",
"OriginalName": "-u",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "Close",
"OriginalName": "-c",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "Switch",
"Position": 2147483647,
"Name": "NoPrompt",
"OriginalName": "-y",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": [
{
"ParameterSetName": "default",
"Handler": "Read-HandleOutput",
"HandlerType": "Function",
"StreamOutput": false
}
]
},
{
"Verb": "Show",
"Noun": "Dll",
"OriginalName": "listdlls.exe",
"OriginalCommandElements": [
"-accepteula",
"-nobanner"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "Name",
"OriginalName": "-d",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "Process",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 2147483647,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Get",
"Noun": "LogonSession",
"OriginalName": "logonsessions.exe",
"OriginalCommandElements": [
"-nobanner",
"-c"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": [
{
"ParameterSetName": "Default",
"Handler": "$args[0] | ConvertFrom-Csv",
"HandlerType": "Inline",
"StreamOutput": false
}
]
},
{
"Verb": "Get",
"Noun": "NtfsInfo",
"OriginalName": "ntfsinfo.exe",
"OriginalCommandElements": [
"-accepteula",
"-nobanner"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "DriveLetter",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Show",
"Noun": "NamedPipe",
"OriginalName": "pipelist.exe",
"OriginalCommandElements": [
"-nobanner",
"-accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Start",
"Noun": "PsExec",
"OriginalName": "psexec.exe",
"OriginalCommandElements": [
"--nobanner",
"--accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "ComputerName",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "Command",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 1,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "Arguments",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 2,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "Switch",
"Position": 2147483647,
"Name": "System",
"OriginalName": "-s",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": [
{
"ParameterSetName": "Default",
"Handler": "$args[0] | ConvertFrom-Csv",
"HandlerType": "Inline",
"StreamOutput": false
}
]
},
{
"Verb": "Show",
"Noun": "LoggedOnAccount",
"OriginalName": "psloggedon.exe",
"OriginalCommandElements": [
"-nobanner",
"-accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "Local",
"OriginalName": "-l",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "NoLogonTimes",
"OriginalName": "-x",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "string",
"Position": 2147483647,
"Name": "ComputerName",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 1,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "string",
"Position": 2147483647,
"Name": "User",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 1,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Sync",
"Noun": "Disk",
"OriginalName": "sync.exe",
"OriginalCommandElements": [
"-nobanner",
"-accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "string",
"Position": 2147483647,
"Name": "Drive",
"OriginalName": "",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 1,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "FlushRemovableDrive",
"OriginalName": "-f",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
},
{
"ParameterType": "switch",
"Position": 2147483647,
"Name": "EjectRemovableDrive",
"OriginalName": "-e",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
},
{
"Verb": "Find",
"Noun": "Domain",
"OriginalName": "whois.exe",
"OriginalCommandElements": [
"-nobanner",
"-accepteula"
],
"Platform": [
"Windows"
],
"Elevation": null,
"Aliases": null,
"DefaultParameterSetName": null,
"SupportsShouldProcess": false,
"ConfirmImpact": null,
"SupportsTransactions": false,
"NoInvocation": false,
"Description": null,
"Usage": null,
"Parameters": [
{
"ParameterType": "String",
"Position": 2147483647,
"Name": "DomainName",
"OriginalName": "-v",
"OriginalText": null,
"Description": null,
"DefaultValue": null,
"DefaultMissingValue": null,
"ApplyToExecutable": false,
"AdditionalParameterAttributes": null,
"Mandatory": false,
"ParameterSetName": null,
"Aliases": null,
"OriginalPosition": 0,
"ValueFromPipeline": false,
"ValueFromPipelineByPropertyName": false,
"ValueFromRemainingArguments": false,
"NoGap": false
}
],
"Examples": [],
"OriginalText": null,
"HelpLinks": null,
"OutputHandlers": null
}
],
"$schema": "https://aka.ms/PowerShell/Crescendo/Schemas/2021-11"
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment