Jeff Stokes's Avatar

Jeff Stokes

@windowsperf.bsky.social

Windows Debugging, Perf analytics, cybersecurity, VDI, Deployment Principal EE at Tanium. Thoughts and words my own Author, speaker, debug engineer, perf analytics guy and gamer https://illuminati.services

180 Followers  |  410 Following  |  20 Posts  |  Joined: 22.06.2023  |  2.2948

Latest posts by windowsperf.bsky.social on Bluesky

How to read a shutdown trace from NETSH and WPRUI to home in on what PID is doing what network traffic at shutdown So in my last post, I described a method for homing in on who is doing what on the network whilst a machine is shutting down. I expect some, a few, random noise data points represented by PID 0 due to requests being made and then the process being killed before the network activity happens. Or perhaps some last throes of a zombied process finally being cleaned up, 

How to read a shutdown trace from NETSH and WPRUI to home in on what PID is doing what network traffic at shutdown

So in my last post, I described a method for homing in on who is doing what on the network whilst a machine is shutting down. I expect some, a few, random noise data points…

29.04.2025 16:59 — 👍 1    🔁 0    💬 0    📌 0
How to collect a netsh and WPR trace for shutdown specific symptoms In the event you have something that only impacts an endpoint when it is being logged off/shutdown, you can do the following to collect declarative data. mkdir C:\temp cd C:\temp netsh trace start capture=yes correlation=yes l report=no tracefile=C:\temp\netshtrace.etl then follow it up with the instructions in this post: This will shutdown the machine. Power it back up, your WPR recording is in Documents\WPR files\

How to collect a netsh and WPR trace for shutdown specific symptoms

In the event you have something that only impacts an endpoint when it is being logged off/shutdown, you can do the following to collect declarative data. mkdir C:\temp cd C:\temp netsh trace start capture=yes correlation=yes l…

25.04.2025 21:53 — 👍 1    🔁 0    💬 0    📌 0
Preview
Raiding YouTube for WoW Data: Building a Smarter Scraper (Part 3) The Key to Scraping YouTube: Planning an Efficient Route In our last run, our scraper successfully raided the WoW-only channels, defeating bosses and amassing a wealth of comments. But no…

#Gaming #datascience

24.04.2025 18:31 — 👍 1    🔁 0    💬 0    📌 0
Preview
AMD User Experience Proxy and handle leaks This is an odd fellow here. As you can see in the image below, AUEPMaster has 157k handles. Yesterday it had over 1 million but I failed to capture a screenshot before reboot. This hasn't impacted game performance as far as I can tell, just an annoyance. Wondering if it's actually working as intended, does it have a security hole, etc...

AMD User Experience Proxy and handle leaks

This is an odd fellow here. As you can see in the image below, AUEPMaster has 157k handles. Yesterday it had over 1 million but I failed to capture a screenshot before reboot. This hasn't impacted game performance as far as I can tell, just an annoyance.…

15.03.2025 22:01 — 👍 2    🔁 0    💬 0    📌 0

Thanks for this

14.03.2025 14:14 — 👍 0    🔁 0    💬 0    📌 0
Preview
PSA: Dell Peripheral Manager causes zombie processes DPM causes zombie processes, software version 2.0.0.72

illuminati.services/2025/02/27/p...

27.02.2025 17:55 — 👍 0    🔁 0    💬 0    📌 0

Can't wait for this to release!

19.01.2025 02:15 — 👍 0    🔁 0    💬 0    📌 0
Enable Certificate Padding Check: REG_SZ or REG_DWORD? Summary

Check out Aaron Margosis' writeup on CVE-2013-3900, the blast from the past that never really remediated.

14.01.2025 06:10 — 👍 1    🔁 0    💬 1    📌 0
Preview
Private prisons are shrouded in secrecy. I took a job as a guard to get inside—then things got crazy This is the biggest investigation we’ve ever published.

Trump's promise of mass deportation has caused private prison stock to soar. Time to re-read Shane Bauer's incredible investigation where he went undercover for months as a private prison guard. It's long, it's harrowing, it won all the awards: www.motherjones.com/politics/201...

22.11.2024 19:39 — 👍 583    🔁 292    💬 31    📌 21
Post image

I'M ALIVE!!! Fuck you, Schrödinger!

21.11.2024 04:38 — 👍 64701    🔁 9209    💬 1009    📌 557
Post image 22.11.2024 12:47 — 👍 63534    🔁 8061    💬 1340    📌 531
Post image

👀

21.11.2024 21:29 — 👍 596    🔁 61    💬 56    📌 68
Preview
How We Harnessed LLMs for Security and Why Testing is Our Secret Weapon Large language models (LLMs) are potent tools, however, their default configurations often fall short in providing the accuracy and consistency required for reliable, critical analysis. In this post, ...

www.dryrun.security/blog/how-we-...

21.11.2024 20:44 — 👍 1    🔁 1    💬 0    📌 0

I’m saying it now with hopes that it sinks in: Donald Trump cannot take any oath of office until he is granted amnesty for breaking the last one he swore. That’s just straight up in the Constitution. 2/3 of each House. That’s the bar.

21.11.2024 15:10 — 👍 2589    🔁 707    💬 102    📌 150
Post image

BREAKING: Gaetz withdraws from consideration for attorney general.

21.11.2024 17:27 — 👍 2462    🔁 593    💬 219    📌 793
Preview
Gootloader’s Pivot from SEO Poisoning: PDF Converters Become the New Infection Vector Three weeks ago, Gootloader samples suddenly dried up. This has happened before, so I switched VPNs and tried new locations—coffee shops, friends’, and family’s Wi-Fi networks—but still couldn’t re…

gootloader.wordpress.com/2024/11/07/g... #cybersecurity

21.11.2024 15:44 — 👍 0    🔁 0    💬 0    📌 0

BREAKING NEWS:

The Matt Gaetz file has officially been leaked:

An “unknown and unauthorized third party” has gained access to depositions tied to Matt Gaetz, a source says.

RT if you’re ready to see it. 🍿

19.11.2024 16:29 — 👍 18083    🔁 8551    💬 880    📌 508
Post image

Meet a coworker for lunch yesterday, he had a passenger

18.11.2024 17:24 — 👍 0    🔁 0    💬 0    📌 0

It worked for me a week ago

18.11.2024 17:18 — 👍 1    🔁 0    💬 0    📌 0
Preview
The rise of Bluesky, and the splintering of social Welcome to The Debrief with Mat Honan, your weekly take on the tech news that really matters, links to stories we love, and the occasional recommendation.

The rise of Bluesky and Threads, coupled with the fleeing of users from X, suggests a long-term shift away from centralized social media.

18.11.2024 14:45 — 👍 214    🔁 45    💬 10    📌 4

Yeah dunno but that was a fun game to watch, for a change :D

17.11.2024 04:28 — 👍 1    🔁 0    💬 1    📌 0

I'm happy to have found you here

17.11.2024 04:22 — 👍 0    🔁 0    💬 0    📌 0

Please follow

16.11.2024 23:09 — 👍 3    🔁 0    💬 0    📌 0

Yeah I deleted my x account last night after archiving it

16.11.2024 23:02 — 👍 0    🔁 0    💬 0    📌 0
Preview
Google Gemini tells grad student to 'please die' First true sign of AGI – blowing a fuse with a frustrating user?

Wow Gemini was cranky! www.theregister.com/2024/11/15/g...

16.11.2024 13:33 — 👍 1    🔁 0    💬 0    📌 0
Post image

I'm this old

16.11.2024 06:19 — 👍 1    🔁 0    💬 0    📌 0

I like them, great smile too :D

16.11.2024 05:02 — 👍 1    🔁 0    💬 0    📌 0
Preview
What is the best thing that has ever happened to you for being nice? Jeff Stokes's answer: I had a blind request on LinkedIn a few years ago. A police officer in a small-ish college town asking if I could help mentor him in the IT field. I agreed because he seemed pass...

www.quora.com/What-is-the-...

16.11.2024 04:55 — 👍 4    🔁 0    💬 0    📌 0

If you are in cybersecurity repost this so we can all follow each other 😬

15.11.2024 16:53 — 👍 82    🔁 115    💬 12    📌 7

Wow

19.09.2023 19:21 — 👍 0    🔁 0    💬 0    📌 0

@windowsperf is following 13 prominent accounts