zodiacon / ProcMonX

Extended Process Monitor-like tool based on Event Tracing for Windows

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

ProcMonX

Extended Process Monitor-like tool based on Event Tracing for Windows

The classic Sysinternals tool Process Monitor uses a file system minifilter, registry minifilter and process/thread callbacks to get the information it provides.

An alternative way is to use Event Tracing for Windows (ETW) to get this information, without the need for a kernel driver. (Process Monitor does use ETW for network events).

See more info at this blog post.

ProcMonX

About

Extended Process Monitor-like tool based on Event Tracing for Windows

License:MIT License


Languages

Language:C# 100.0%