ARTICLE Process Monitor v2.7 - Monitoring tool for Windows
Saturday 26 September 2009 - 808 read - ( Keywords : Enumeration , Forensics , Monitoring , Process Monitor )
Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon.Process Monitor adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file.
Features
- More data captured for operation input and output parameters
- Non-destructive filters allow you to set filters without losing data
- Capture of thread stacks for each operation make it possible in many cases to identify the root cause of an operation
- Reliable capture of process details, including image path, command line, user and session ID
- Configurable and moveable columns for any event property
- Filters can be set for any data field, including fields not configured as columns
- Advanced logging architecture scales to tens of millions of captured events and gigabytes of log data
- Process tree tool shows relationship of all processes referenced in a trace
- Native log format preserves all data for loading in a different Process Monitor instance
- Process tooltip for easy viewing of process image information
- Detail tooltip allows convenient access to formatted data that doesn’t fit in the column
- Cancellable search
- Boot time logging of all operations
POSTSCRIPTUM
COMPLIANCE MANDATES
Forensics : PCI DSS 10.2, 12.9, A.1.4*, SOX DS7, HIPAA 164.308(a)(1) and (a)(6), FISMA IR-7, ISO 27001/27002 13.2.1, 13.2.3
*Shared Hosting Providers OnlyRELATED ARTICLES
Enumeration,
Forensics,
Monitoring,
Process Monitor,
25 April 2010 : Process Monitor v2.9 released
26 September 2009 : Process Monitor v2.7 - Monitoring tool for Windows
Security Dashboard








