首页
社区
课程
招聘
[转帖]Process Monitor v3.52
发表于: 2019-4-25 07:59 6686

[转帖]Process Monitor v3.52

2019-4-25 07:59
6686

Process Monitor v3.52


Introduction

Process Monitoris an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities,FilemonandRegmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. Its uniquely powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit.

Overview of Process Monitor Capabilities

Process Monitor includes powerful monitoring and filtering capabilities, including:

More data captured for operation input and output parameters

Non-destructive filters allow you to set filters without losing data

Capture of thread stacks for each operation make it possible in many cases to identify the root cause of an operation

Reliable capture of process details, including image path, command line, user and session ID

Configurable and moveable columns for any event property

Filters can be set for any data field, including fields not configured as columns

Advanced logging architecture scales to tens of millions of captured events and gigabytes of log data

Process tree tool shows relationship of all processes referenced in a trace

Native log format preserves all data for loading in a different Process Monitor instance

Process tooltip for easy viewing of process image information

Detail tooltip allows convenient access to formatted data that doesn't fit in the column

Cancellable search

Boot time logging of all operations

The best way to become familiar with Process Monitor's features is to read through the help file and then visit each of its menu items and options on a live system.

_https://docs.microsoft.com/zh-cn/sysinternals/downloads/procmon

[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

上传的附件:
收藏
免费 3
支持
分享
最新回复 (3)
雪    币: 16420
活跃值: (1675)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
介绍
进程监视是一种高级的Windows监视工具,它显示实时文件系统、注册表和进程/线程活动。它结合了两个遗留系统内部实用程序filemonandregmon的功能,并添加了大量增强功能,包括丰富的和非破坏性的筛选、综合的事件属性(如会话ID和用户名)、可靠的进程信息、完整的线程堆栈以及对每个操作的集成符号支持、同步日志。转到一个文件,等等。它独特的强大功能将使进程监视器成为系统故障排除和恶意软件搜索工具包中的核心实用程序。
流程监控功能概述
过程监控包括强大的监控和过滤功能,包括:
为操作输入和输出参数捕获更多数据
非破坏性筛选器允许您设置筛选器而不丢失数据
捕获每个操作的线程堆栈使在许多情况下能够识别操作的根本原因
可靠捕获进程详细信息,包括映像路径、命令行、用户和会话ID
任何事件属性的可配置和可移动列
可以为任何数据字段设置筛选器,包括未配置为列的字段
高级日志记录体系结构可扩展到数以千万计的捕获事件和千兆字节的日志数据
流程树工具显示跟踪中引用的所有流程的关系
本机日志格式保留所有数据以便在其他进程监视器实例中加载
流程工具提示,便于查看流程图像信息
详细信息工具提示允许方便地访问不适合列的格式化数据
可取消搜索
所有操作的启动时间日志记录
熟悉Process Monitor功能的最佳方法是阅读帮助文件,然后在实时系统上访问其菜单项和选项。
_ https://docs.microsoft.com/zh-cn/sysinternals/downloads/procmon
2019-4-25 08:48
0
雪    币: 219
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
3
process monitor 有开源吗?
2021-7-8 13:59
0
雪    币: 9
活跃值: (180)
能力值: ( LV6,RANK:90 )
在线值:
发帖
回帖
粉丝
4
谢谢分享
2022-7-10 22:03
0
游客
登录 | 注册 方可回帖
返回
//