Sysinternals: Process Monitor deep dive (demo) | ProcMon, registry, process, Windows | Microsoft

Поділитися
Вставка
  • Опубліковано 23 січ 2025

КОМЕНТАРІ • 8

  • @smithnigelw
    @smithnigelw Рік тому

    Great! I’ve used ProcMon many times, but learned many new techniques from this video.

  • @QQ_Victory
    @QQ_Victory 2 роки тому +1

    Great deep dive into ProcMon! Very interesting.

  • @berndeckenfels
    @berndeckenfels 2 роки тому

    22:40 enabling those symbols not only translated the addresses but also showed much more user mode stack frames? Is that local calls in same module or another effect?

  • @PhO3NiX96
    @PhO3NiX96 10 місяців тому

    I'm struggling to find a way to trace what script/program writes down a specific file under a specific directory at startup, meaning like when I start my PC, the file is already there so I can't trace after using Procmon, which would mean I need to use the boot thing mentioned in the video but for some reason I can't find what program writes down this file.

  • @Ciaran401
    @Ciaran401 Рік тому

    A demo of you loading your own symbols would be great

  • @saeed5508
    @saeed5508 Рік тому +1

    Where have you got that Isfahani Carpet?

  • @gin42069
    @gin42069 Рік тому

    how to unload procmon can u help me?

  • @Ehren1337
    @Ehren1337 2 роки тому +2

    time to move on to windows 11